The Coca-Cola Company has suspended U.S. production of its Fairlife dairy products following a ransomware attack on its systems [1, 2, 3].
This shutdown disrupts the supply chain for a brand that generates approximately $1 billion in revenue [1], highlighting the vulnerability of critical food and beverage production lines to cyber warfare.
Coca-Cola said that an unauthorized third party gained access to production-related systems [1, 3]. In response, the company halted operations in the United States to investigate the breach and implement recovery protocols [2, 4]. The company said it immediately activated incident response and business continuity protocols after detecting the unauthorized access [5].
While U.S. facilities are offline, reports indicate that Canadian operations remained unaffected by the attack [2, 6]. The company has not yet provided a timeline for when production will resume, saying that production will remain suspended in the United States following the hack [7].
In a filing with the Securities and Exchange Commission, Coca-Cola said, "The full scope, nature and impacts of the incident are not yet known" [2]. The breach specifically targeted the systems used to manage the manufacturing of Fairlife products, a high-protein dairy line that has become a significant part of the company's portfolio [1, 2].
The incident occurs as ransomware attacks against industrial control systems increase globally. By targeting the production layer rather than just administrative data, attackers can force immediate operational shutdowns to increase leverage for ransom payments [3, 4].
“"Production will remain suspended in the United States following the hack,"”
This incident underscores a shift in cybercrime where attackers target operational technology (OT) rather than just information technology (IT). By disabling the physical production of a billion-dollar brand, the attackers create immediate financial pressure and supply chain instability. The suspension of U.S. operations while Canadian plants remain active suggests a localized or network-segmented breach, but the total halt of U.S. output demonstrates the high risk of systemic failure when production systems are compromised.



