The Coca-Cola Co. said a cyberattack forced it to temporarily halt Fairlife milk operations in the U.S. after an unauthorized third-party user accessed the brand's production systems. Coca-Cola said it believes the incident was a ransomware event.
The company said it detected the issue Thursday, began investigating with external cybersecurity experts and notified law enforcement. It said the full scope, nature and impacts of the incident are not yet known, and it is unclear when the breach occurred.
Fairlife's U.S. production operations are temporarily suspended, but operations in Canada are running normally. Coca-Cola said the breach has not affected product quality or safety, even as the disruption hits a brand that sells milk and protein shakes and generates annual sales topping $3 billion.
The company bought Fairlife from Select Milk Producers in 2020 for roughly $7 billion, and the brand remains one of Coca-Cola's 200 brands across its drinks portfolio. That scale helps explain why the shutdown matters now: a problem inside production systems can ripple through a business that sits well beyond a niche dairy label.
What Coca-Cola has not said is when Fairlife's U.S. production systems will be restored. It said it is working to complete the investigation and bring the impacted operations back online, but the unanswered question is how long that will take and whether the disruption will spread beyond the temporary halt already in place.

