As reported, Coca-Cola’s Fairlife-branded plant-based dairy alternatives operations have been hit by a cyber attack. If you stop producing beverages, dairy, or food for even just a few days, there are massive supply chain, retailer, inventory, and revenue disruptions.
For a manufacturing operation like Fairlife’s, getting back online isn’t as simple as flipping a switch. Shane Barney, chief information security officer at Keeper Security, explains the added complexity: “Production systems depend on specialized hardware and software that wasn’t built for today’s threat landscape … Resuming operations safely means validating process integrity, not just IT systems.”
Coca-Cola isn’t alone in facing this kind of disruption. Past ransomware incidents at Arizona Beverages in 2019 and food distributor giant UNFI last year led to weeks-long disruptions to production lines, leaving some grocery shelves empty.
“Fairlife, Arizona Beverages, UNFI, and others show how an intrusion that begins in ordinary IT can disrupt production and distribution.” Harry Thomas, founder and CTO at Frenos said. “The incidents affecting the food and beverage industry reflect a broader trend we’re seeing across operational technology environments,” he added. “Manufacturing organizations often rely on a combination of legacy industrial control systems, modern cloud infrastructure and third-party vendors.”
According to Thomas, attackers rarely need sophisticated exploits to break in; compromised credentials, remote access services, or other identity-related weaknesses are usually enough. This gives them a way to move laterally through the network, adding a layer of complexity that makes both prevention and recovery harder.
Until Coca-Cola gets its systems back online, it’s unclear how long Fairlife’s shelves will stay empty.
Photo: Coca-Cola