Anubis claimed it encrypted Fairlife servers and stole one terabyte of data, while Arctic Wolf researchers said they observed screenshots on the group's leak site and Coca-Cola had suspended United States production during an investigation, Cybersecurity Dive reported. [1]
The claim stops earlier than the paper's July 20 Craneware account, which accepted company-reported access and file theft while withholding victim and harm counts, because Coca-Cola had not publicly named Anubis or an access path.
Neither the volume nor the contents were independently verified, and the authorized record established no public leak, ransom payment, restoration, notice, customer impact, or food-safety problem; Coca-Cola separately said product safety and quality were unaffected. [1]
No verified X status was recovered, and an outlet's share-intent link is not a post, so supply panic and criminal attribution remain unobserved on the platform; Cybersecurity Dive's headline appropriately says the group claims credit rather than declaring a forensic finding.
Known Anubis use of stolen credentials or old vulnerabilities does not identify Fairlife's route, leaving the next defensible ledger with indicators, affected systems and sites, privileged accounts, encrypted assets, validated exfiltration, record types, named populations, legal notices, regulator filings, restoration milestones, demand, payment, production restart, inventory, supply effects, customer harm, and independent attribution with published methods, confidence, limitations, and reproducible independently reviewed technical evidence after the July 22 cutoff. [1]
-- DAVID CHEN, Beijing