Everest Hit Coca-Cola Twice. The Middle East Passports in the Fairlife Leak Are the Fingerprint.
- Patrick Duggan
- 2 hours ago
- 4 min read
On July 16, Coca-Cola told the world that its Fairlife dairy unit had stopped making milk in the United States. The wording in the disclosure was the careful kind: an unauthorized third party reached "a portion" of its systems, production-related systems included, the investigation is ongoing, product safety was not affected, law enforcement is notified. No gang was named. No terabytes were counted. It read like every other breach notice — the corporate shrug you learn to skim past.
Twenty-four hours later the shrug got a name. Everest posted Fairlife to its Tor leak site and claimed 22 terabytes. And buried in the sample were the files that turn this from a generic ransomware note into an attribution: passport scans, visa copies, and national IDs of employees in the Middle East.
That detail is the whole story. Because Coca-Cola's Middle East division was already an Everest victim earlier this year.
The same crew, the second time
Everest is not a mystery to us. We imported its profile on June 29 — a Russian-speaking data-extortion crew, active since roughly December 2020, that started as classic double-extortion (steal the files, then encrypt them) and has since dropped the encryptor almost entirely. It sells network access as an initial-access broker and it runs pure data-theft extortion off a Tor leak site. We filed it as one of the brands that typifies the 2026 shift away from encryption toward naked leverage: give me money or the files go public. No lockout required.
That profile was written three weeks before Coca-Cola's milk went dark, and it describes this attack exactly.
Everest spent the front half of 2026 on a Middle East run — Coca-Cola's Middle East division, the Abu Dhabi Department of Culture and Tourism, Jordan Kuwait Bank. It has a 365-victim ledger, with healthcare its single most-hit sector, and it has listed names most people think are too big to end up on a leak site: BMW, Collins Aerospace, Frost Bank. So when Middle East employee passports show up inside a "Fairlife" dump, the honest read is not that Everest suddenly cared about Illinois dairy. It is that Fairlife's parent shares an identity fabric with a business Everest was already standing inside, and the Middle East HR files rode along.
That is what an initial-access broker looks like when it stops being theoretical. One foothold, one directory, one set of trust relationships — and a milk brand in the US Midwest inherits the blast radius of a beverage division on another continent.
Why the milk actually stopped
The part that should worry a board more than the passports is that production halted at all.
Data extortion, by definition, does not need to touch the plant floor. You copy files, you threaten to publish, you never go near an operational technology network. Everest's whole 2026 posture is built to skip the encryptor. And yet Fairlife stopped bottling in the US while its Canadian operations kept running.
That gap is the tell. When an IT-only data theft forces an OT shutdown, it is almost never because the attacker reached the bottling line. It is because the victim could not prove they had not — so they pulled the plug themselves, out of an abundance of caution, because segmentation between the business network and the production network was not clean enough to rule it out with confidence. The shutdown is not evidence of how deep Everest got. It is evidence of how little Fairlife could see. Canada staying up while the US went down suggests the two run on different enough infrastructure that Canada could be cleared and the US could not, quickly.
For a food and beverage operator, that is the expensive lesson, and it costs the same whether the attacker ever had OT access or not.
What we can and can't hand you
Here is the honest part, because the honest number is the strong one.
This is an attribution story, not a blocklist story. We are not going to hand you a clean set of IPs to drop into your firewall for Everest, and any feed that claims to is selling you the Tor leak site dressed up as intelligence. Everest gets in through phishing and brute-forced RDP and access it buys from other brokers — commodity front doors, not a fixed C2 fingerprint you can enumerate. Our feed carries zero attributed network indicators for this crew, and that is the correct number, not a gap we are hiding. You do not defend against Everest by blocking an address. You defend against it by killing exposed RDP, by phishing-resistant MFA on every remote path, and by segmenting your business network from your plant hard enough that a lawyer's-caution shutdown is never the only option you have left.
What we can hand you is the thing that was true before the milk stopped: we named this crew and its exact playbook — encryptor dropped, data-theft only, IAB model, Middle East run — on June 29. The receipt for this one is not "we saw the Fairlife IP." It is "we described the operator three weeks before it curdled Coca-Cola's second brand of the year, and the passports in the leak match the division it already owned."
We are about 95 percent confident in the two-hits-one-crew read. The remaining five percent is the space between a leak site's claim and a confirmed forensic timeline, and Coca-Cola's investigation is still open. We will name it plainly if that five percent turns out to be where the truth was hiding. But the Middle East passports are a hard thing to explain any other way, and Everest is not a crew that puts files on its site it did not take.
The takedown headlines will come later, if they come at all. The useful work was the part that happened before anyone at Fairlife knew the milk was going to stop.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
