Two Different Ransomware Gangs Now Claim They Hacked Coca-Cola's Fairlife. One Says 22 Terabytes, One Says One. Here's How to Read a Fight Over a Corpse.
- Patrick Duggan
- 2 hours ago
- 5 min read
On July 16, Coca-Cola said its Fairlife dairy unit had stopped making milk in the United States — an unauthorized third party, "a portion" of its systems, production included, investigation ongoing, no gang named. The corporate shrug you learn to skim past. Since then, two ransomware gangs have stepped up to claim it, and they don't agree with each other. That disagreement is the most useful thing in this story, because learning to read it is a skill that outlasts any single breach.
The two claims
Everest posted Fairlife to its Tor leak site and claimed 22 terabytes, and buried in its sample were the files that make its claim hard to wave off: passport scans, visa copies, and national IDs of employees in the Middle East.
Anubis — a separate ransomware-as-a-service operation that emerged in December 2024 — added Fairlife to its dark-web leak site and claimed roughly one terabyte.
Same victim. A 22× gap in the alleged haul. Two unrelated crews. Independent verification of either number has, so far, proved elusive. So which one actually did it?
How to weigh a double claim (because you'll see more of these)
When two gangs claim one victim, there are only a few explanations, and you rank them by evidence, not by who shouted first:
One crew actually breached it; the other is piggybacking on a famous name for clout or to pressure a payment. This is common and cheap — a leak-site listing costs nothing and a Coca-Cola brand draws eyes.
The data was resold or shared — an initial-access broker sold the same foothold twice, or one crew bought the other's dump and re-listed it.
Two genuinely separate intrusions of the same soft target in the same window.
Here's the honest weighing. Everest's claim carries a corroborating fingerprint that Anubis's, so far, does not. Middle East employee passports are a strange thing to find in an Illinois dairy dump — until you remember that Everest already hit Coca-Cola's Middle East division earlier this year. We know Everest as a Russian-speaking, encryptor-dropped, pure-data-theft extortion crew and an initial-access broker; we imported its profile on June 29, three weeks before the milk went dark, and it described a Middle East run, a 365-victim ledger, and exactly this playbook. So the passports aren't random — they're the residue of a parent company that shares an identity fabric with a division Everest was already standing inside. That's what an access broker looks like when it stops being theoretical: one foothold, one directory, and a Midwest milk brand inherits the blast radius of a beverage division on another continent.
Anubis's terabyte, by contrast, arrives without that connective tissue in the public reporting. That doesn't make it false — it makes it unproven, and the honest label for an unproven claim is "unproven," not "fake." It could be a separate access, a resold dump, or a piggyback. We're not going to declare for you; we're going to tell you the one claim has a fingerprint and the other, right now, has an assertion.
The practical lesson for a defender or a journalist: don't let the biggest number win. "22 terabytes" is a better headline than "one," and gangs know it — extortion leverage runs on inflated counts. Rank the claims by corroboration — does the sample tie to something independently known? — not by volume or by which leak site you saw first.
Why the milk actually stopped — and this part doesn't care who did it
Set the attribution fight aside, because the most expensive fact in this story is agnostic to it: production halted at all.
Data extortion, by definition, doesn't need to touch the plant floor. You copy files, you threaten to publish, you never go near an operational-technology network — and that's the modern posture both these crews mostly run. Yet Fairlife stopped bottling in the US while its Canadian operations kept running.
That gap is the tell. When an IT-only data theft forces an OT shutdown, it's almost never because the attacker reached the bottling line. It's because the victim couldn't prove they hadn't — so they pulled the plug themselves, out of caution, because the segmentation between the business network and the production network wasn't clean enough to rule it out fast. The shutdown isn't evidence of how deep anyone got. It's evidence of how little Fairlife could see. Canada staying up while the US went down suggests the two run on different enough infrastructure that Canada could be cleared quickly and the US couldn't. For a food-and-beverage operator, that's the lesson, and it costs the same whether either gang ever had OT access.
What we can and can't hand you
Honest, as always. This is an attribution story, not a blocklist story. We are not going to hand you clean IPs for Everest or Anubis, and any feed that claims to is selling you a Tor leak site dressed up as intelligence. Both crews get in through phishing, brute-forced RDP, and access bought from brokers — commodity front doors, not a fixed C2 fingerprint you can enumerate. Our feed carries zero attributed network indicators for either crew on this event, and that's the correct number, not a gap we're hiding. You don't defend against this by blocking an address. You defend against it by killing exposed RDP, phishing-resistant MFA on every remote path, and segmenting your business network from your plant hard enough that a lawyer's-caution shutdown is never the only move you have left.
What we can hand you is the reconciliation: two gangs are claiming Fairlife, the counts are 22TB versus 1TB, and the tiebreaker isn't the number — it's that Everest's dump carries Middle East passports matching a Coca-Cola division it already owned, and Anubis's doesn't, yet. We named Everest and its exact playbook on June 29. We flag Anubis's claim as real-but-unverified. And we tell you plainly that the milk stopping had nothing to do with which of them wins the argument.
We hold this at 95 percent, as always — the claims, the terabyte counts, and the Everest/Anubis attributions are the gangs' own leak-site postings and the trade-press reporting on them, not our own capture. Competing extortion claims are exactly the kind of thing where certainty is a lie; the honest output is a weighting, and ours is above.
Sources: Coca-Cola's July 16 disclosure and the ransomware claims via BleepingComputer, The Register, and Cyber Daily (Anubis, ~1TB); Everest's 22TB claim and its prior Coca-Cola Middle East hit via trade-press coverage and our own imported Everest adversary profile (2026-06-29). No attributed network indicators exist for either crew on this event; this is an attribution weighting, not a blocklist.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.




Comments