
The Fairlife Attack Shows Why Manufacturers Can’t Afford to Guess
Over the past several weeks, the cyberattack against Coca-Cola’s Fairlife dairy business has continued to evolve.
On July 16, Coca-Cola disclosed that Fairlife had experienced a ransomware event involving unauthorized access to a portion of its systems, including production-related systems, prompting the company to temporarily suspend U.S. production.
Days later, ransomware group Anubis claimed responsibility for the attack, alleging it had stolen company data. Coca-Cola has not publicly verified the group’s claims. Subsequent reporting has provided additional details about Anubis and its tactics.
On July 27, Coca-Cola announced that the majority of production had resumed, adding that product quality and safety had not been impacted and that existing inventory had largely prevented retail disruptions.
From an OT perspective, the production shutdown raises an important question: What conditions would make halting operations the safest course of action?
While many immediately assumed attackers had compromised industrial control systems, there is no public evidence that occurred. For manufacturers operating in highly regulated industries like food and beverage, the greater concern is whether they can still trust the systems responsible for producing safe, compliant products. When that confidence is lost, temporarily stopping production may be the only responsible decision.
Modern Manufacturing Depends on Connected Systems
Modern manufacturing relies on far more than PLCs and SCADA. Enterprise applications, manufacturing execution systems (MES), historians, quality systems, engineering workstations, and industrial control systems continuously exchange data to support production, compliance, and operational decision-making.
Those connections improve efficiency but also create operational dependencies that didn’t exist in traditional OT environments. Many organizations still lack a complete understanding of those dependencies or the data flows between systems. Without that visibility, determining what was affected during a cyberattack becomes significantly more difficult.
Understanding those relationships before an incident occurs is critical. Visibility into assets, communications, and data flows allows organizations to quickly determine what systems were impacted, what can safely continue operating, and where recovery efforts should begin.
Production Can Continue. Shipping the Product Is Another Story.
Many industrial processes are capable of operating in a disconnected mode. The machinery itself may continue running safely without constant connectivity to enterprise systems. But continuing to manufacture a product isn’t always the same as being allowed to release it.
Food manufacturers provide a clear example. USDA-regulated facilities must continuously monitor and document refrigeration temperatures, pasteurization cycles, quality measurements, and other critical process data.
If a temperature deviation occurs, manufacturers need to know:
- How long did it last?
- Which production areas were affected?
- How quickly was it corrected?
- Which products were exposed?
These aren’t operational metrics collected for convenience. They’re regulatory requirements used to demonstrate product safety and compliance.
If manufacturers cannot verify that information because monitoring, reporting, or supporting systems may have been compromised, they may no longer be able to certify the safety of the product. Entire production runs may have to be discarded.
Why Manufacturing Recovery Is Different
Once ransomware is discovered, organizations know someone gained access to their environment. What they don’t know is what happened before the attack was detected.
That’s what makes incident response in manufacturing fundamentally different from many enterprise environments. The challenge isn’t simply removing the threat or restoring systems. It’s determining whether the integrity of the production process can still be trusted. Until that question can be answered with confidence, organizations are often forced to make difficult operational decisions, even if it means temporarily halting production.
Investigations can take days or even weeks. Attackers may have stolen data, modified configurations, or altered system parameters. Until investigators determine what occurred, organizations cannot assume production systems remain trustworthy.
Consider an automated dairy production line where pasteurization temperatures and processing times are tightly controlled and continuously recorded. If investigators cannot verify those process parameters remained unchanged during the attack, every product produced during that period becomes suspect.
Manufacturers need to be able to demonstrate that those critical process parameters remained unchanged throughout the incident. That’s why Fairlife’s decision to suspend production wasn’t surprising. Before manufacturing could safely resume, the company needed confidence that the systems controlling, monitoring, and validating production had maintained their integrity. Without that assurance, continuing operations would introduce unnecessary operational, regulatory, and product safety risk.
Recovery Starts with Visibility
The ability to recover doesn’t begin when ransomware is discovered. It begins long before the attack occurs. Organizations need a clear understanding of how IT and OT environments interact, what systems exchange data, and which operational processes depend on enterprise infrastructure.
That level of visibility enables responders to answer critical questions much faster:
- Which systems communicated with the compromised environment?
- What production systems were affected?
- Can operations continue safely in an isolated mode?
- What evidence exists that process integrity was maintained?
Without those answers, recovery becomes slower, more disruptive, and significantly more expensive.
Visibility tools can provide much of this insight, but technology alone isn’t enough. Manufacturers also need documented architectures, an understanding of operational dependencies, and incident response plans designed specifically for industrial environments.
Process Integrity Determines Recovery
Coca-Cola has since reported that the majority of Fairlife’s production has resumed and that product quality and safety were not impacted—a positive outcome that demonstrates the value of a disciplined incident response process.
Successful recovery depends on both restoring systems and validating the integrity of manufacturing processes before production resumes.
As IT and OT become increasingly interconnected, maintaining the integrity of operational systems becomes just as important as protecting them from compromise. For regulated manufacturers, the ability to validate process integrity determines whether production resumes or whether products must be discarded.
The fastest recoveries come from organizations that understand their environments, validate the integrity of their manufacturing processes, and restore operations with confidence.
Back

