Coca-Cola refused to pay the ransom. On July 16, 2026, according to Coca-Cola's SEC disclosure, a ransomware attack had stopped production at Fairlife, its dairy subsidiary. Four plants in the United States. Eleven days of interrupted operations. Four days later, according to the Anubis group, Fairlife was listed on its leak site: the group claimed to have stolen 1 terabyte of data and encrypted the entire Nutanix infrastructure, with a deadline set for July 27. Coca-Cola did not negotiate, reported to authorities, and on July 27 Anubis published the data. We analyzed the case and the signal is clear: Coca-Cola's decision was rational — and the reason is a parameter called /WIPEMODE.
/WIPEMODE: why paying the ransom is a losing bet
Anubis offers an operational mode that few ransomwares have: a parameter called /WIPEMODE. When activated, file contents are permanently zeroed. Names remain. Folder structure remains. But content becomes zero bytes. Recovery impossible. Even if you pay.
Paying the ransom guarantees nothing. It is a bet against a group that offers a destructive wiper as a feature. There is no guarantee the attacker will disable /WIPEMODE after payment. There is no way to prove it was not executed before negotiation. Coca-Cola's decision to refuse the ransom, according to FBI and CISA guidance, was the right decision — not the cheap decision. Eleven days of production. Data published. Reputation at stake.
Anubis: origin, operation, and why Fairlife was outside the pattern
Anubis emerged in December 2024 as a rebrand of the Sphinx ransomware, according to reported threat intelligence. RaaS operation, 80/20 split, recruitment in Russophone forums. 83 victims listed on its leak site. Main sector: healthcare. Fairlife was outside the usual pattern — food and agriculture is not the group's focus, which makes the attack a signal of target expansion.
The probable vector was CitrixBleed 2, CVE-2025-5777 — a vulnerability in Citrix NetScaler that leaks session tokens from memory. The attacker reproduces the token and enters as an authenticated user. No password. No MFA. No phishing. The patch was free, available for months. Coca-Cola did not confirm the vector publicly. But the pattern is consistent with Anubis's kill chain: initial access via a stolen session token, limited lateral movement, target on the scheduling ERP.
The cold chain as a target: perishables have deadlines
The Fairlife attack is part of a series. It is the 205th ransomware attack on the food and agriculture sector in 2026, according to reported sector data. The food industry is the 7th most attacked sector by volume. But top 3 in systemic impact.
The history is recurrent. JBS paid $11 million in 2021; twenty percent of US meat capacity went offline. Dole stopped operations in North America in 2023. Nichirei in Japan had 140 refrigerated distribution centers offline in July 2026 — KFC Japan ran out of chicken.
The cold chain is an attractive target for a simple reason: perishables have deadlines. According to reported industry data, one hour of downtime in a food and beverage plant costs on average $1 million. Operating margins of 1.6%. The clock plays in the attacker's favor. Every hour of negotiation is an hour of product lost — and the attacker knows it.
Tech86's diagnosis: SCADA, FSMA, and remote connectivity
When Tech86 evaluates infrastructure at food industry clients, the diagnosis is recurrent. SCADA systems 15 years old on the same VLAN as the office. Temperature evidence — regulatory under FSMA — stored on systems without tested backups. Remote connectivity enabled in cold storage without segmentation.
The probable target of the Fairlife attack was the scheduling ERP. SCADA remained intact. Production stopped because regulation requires the stop when scheduling integrity is compromised. This is what makes ransomware in the cold chain different from ransomware in other sectors: you do not need to encrypt SCADA to stop production. It is enough to compromise the system that schedules what enters and what leaves.
Conclusion: the next attack on the cold chain is a matter of when
Coca-Cola made the right decision. Refusing the ransom is the guidance of the FBI and CISA. But the right decision does not mean the cheap decision. Eleven days of production. Data published. Reputation at stake. The next attack on the cold chain is a matter of when.
At Tech86, we help food industry companies segment SCADA from corporate networks, patch known vectors like CitrixBleed 2, test backups for regulatory evidence, and disable remote connectivity on cold storage by default. /WIPEMODE changed the ransom calculus — paying is no longer a fallback option, it is a bet against a wiper that has no workaround.