Fairlife Cyberattack Halts U.S. Production as Coca-Cola Assesses Operational Impact

The ransomware incident has interrupted manufacturing at one of Coca-Cola’s fastest-growing businesses, although the company says product quality and safety remain unaffected. The Coca-Cola Company has temporarily suspended Fairlife production across the United States after a ransomware attack compromised part of the dairy brand’s technology environment, including systems connected with manufacturing operations.

Coca-Cola disclosed the incident on July 16, 2026, saying an unauthorized third party had gained access to a portion of Fairlife’s systems. Production in Canada was not affected and remained operational at the time of the announcement.

The beverage company characterized the incident as an operational and technology disruption rather than a food-safety event. According to Coca-Cola, there has been no impact on the quality or safety of Fairlife products, which include ultra-filtered lactose-free milk, Core Power protein drinks and nutritional shakes. Coca-Cola has not provided a timetable for restarting its U.S. facilities. The company said it activated its incident-response and business-continuity procedures after identifying the breach and brought in external cybersecurity specialists and other advisers. Law enforcement has also been notified.

The investigation is still in its early stages, leaving several important questions unresolved. Coca-Cola said it has not yet determined the complete scope or nature of the intrusion, which systems and data may have been accessed, or how significantly the shutdown could affect the wider business.

In a filing with the Securities and Exchange Commission, the company said it was not yet able to determine whether the ransomware incident was reasonably likely to have a material effect on its financial position or operating results.

No attacker had publicly claimed responsibility at the time of the initial reporting, and Coca-Cola had not identified a suspected ransomware group. The duration of the production interruption—and the amount of finished inventory available to serve retailers while systems are restored—could help determine whether the incident results in noticeable product shortages.

The shutdown comes at a significant moment for Fairlife. Coca-Cola acquired the remaining 57% of the dairy company in 2020 after initially operating the business as a joint venture with Select Milk Producers. Fairlife announced in 2022 that it had exceeded $1 billion in annual U.S. retail sales, supported by demand for its filtered milk and high-protein beverages.

Coca-Cola has continued committing capital to the brand as it works to expand production capacity. In March 2026, the company announced plans to invest $650 million in its Coopersville, Michigan, operation. The project is expected to add approximately 245,000 square feet, two production lines and 150 jobs, with commercial production on the new lines targeted for 2028.

A separate Fairlife manufacturing facility in Webster, New York, was also scheduled to open during 2026. Together, the projects reflect Coca-Cola’s efforts to increase supply for a brand that has become an important part of its dairy and nutrition portfolio.

The ransomware incident does not necessarily threaten those long-term expansion plans. However, it demonstrates how technology failures can quickly interrupt physical production, even when the underlying event does not compromise the safety of the product itself.

Fairlife’s shutdown is part of a broader pattern of cyberattacks affecting food, agriculture and manufacturing companies. Food and Agriculture Information Sharing and Analysis Center officials told Food Dive that the sector had experienced approximately 205 cyberattacks during 2026 as of the publication of the reference report, accounting for about 4.9% of attacks tracked during the period.

Food manufacturers can be particularly vulnerable to operational disruption because production increasingly depends on interconnected technology used to control equipment, coordinate ingredients, monitor quality and manage distribution. When those systems are isolated as part of an incident response, companies may be forced to stop production even when manufacturing equipment itself has not been physically damaged.

Coca-Cola’s immediate priorities will be to establish how the attackers entered Fairlife’s environment, determine whether information was taken, restore production-related systems securely and resume U.S. manufacturing without creating further risk.

Until that work is completed, the commercial consequences remain uncertain. The length of the shutdown, Fairlife’s available inventory and the speed at which production can be restarted will ultimately determine whether the ransomware event remains a contained technology incident or develops into a broader supply and financial challenge.