The Anubis ransomware operation has named Coca-Cola's Fairlife milk business on its data-leak site, describing it as a major breach at a company owned by the beverage giant. The crew posted the listing twice: first on July 20, 2026, then again on July 27 under a slightly different name and on a different mirror of its site.
Nothing about the claim has been verified. Leak-site entries are marketing written by the extortionists themselves, they are sometimes recycled or exaggerated, and they occasionally describe data taken from a supplier rather than the headline brand. Neither Coca-Cola nor Fairlife, the US ultrafiltered milk producer Coca-Cola took full ownership of in 2020, has publicly acknowledged an incident, and IntelFusions has seen no evidence that any data has actually been published. Read the listing as an accusation and a pressure tactic, not as a confirmed breach.
The repeat posting is the detail worth noting. Crews normally re-list a victim when a negotiation deadline lapses, when they want to restart a stalled conversation, or when they are staging the release of data in tranches. It is also, less flatteringly, what happens when a group is padding its site to look busier than it is.
Who Anubis is
Anubis is a ransomware-as-a-service operation that surfaced in December 2024 as a rebrand of the earlier Sphinx encryptor, a lineage visible in the file extension switching from .sphinx to .anubis. Its operators advertised an affiliate program on the RAMP crime forum in February 2025 with three revenue tracks: conventional ransomware at roughly 80/20 in the affiliate's favor, pure data extortion at about 60/40, and monetizing someone else's stolen access at about 50/50.
The Go-based encryptor uses public-key cryptography, deletes Windows shadow copies, and ships in Windows and Linux variants. It also carries a destructive wipe mode that zeroes out file contents, which removes any prospect of recovery even for a victim who pays. That capability is what makes an Anubis listing worth taking seriously regardless of how this particular claim resolves. Intrusions investigated during 2026 by Arctic Wolf ran on valid VPN credentials and on CitrixBleed 2 (CVE-2025-5777) for initial access, followed by abuse of remote management tools including ScreenConnect, Zoho Assist and MeshAgent, plus Mimikatz for credential theft.
A steady rather than spectacular tempo
Our tracking records 13 Anubis leak-site claims in the past 30 days, a mid-table pace rather than a surge. The most recent surrounding entries are the French insurance brokerage Prelys Courtage on July 28, the US hospitality operator Eagle Crest Communities on July 26, and Bath Fitter on July 20. The group's historic focus has been healthcare, construction, engineering and professional services across Australia, Canada, Peru and the United States, so a large food and beverage brand sits outside its usual pattern. Full history is on our Anubis profile and in the wider United States incident record.
What defenders should take from this
Consumer brands attract claims precisely because the name generates pressure, so the useful response is not to guess whether this one is real. Organizations in Anubis's path should close the access routes the group is known to use: enforce phishing-resistant multi-factor authentication on VPN and remote access, confirm Citrix appliances are patched against CVE-2025-5777 and that sessions issued before patching were invalidated, and alert on remote management agents such as ScreenConnect or MeshAgent appearing where IT never deployed them. Because the wipe mode defeats paying, offline and tested backups are the only reliable answer.
Unverified listings of major brands are a recurring feature of this market. Qilin named Stryker months after the medtech firm ruled out ransomware, and a separate extortion crew this week claimed Ernst and Young, RingCentral and Brinks Home. IntelFusions will update this story if either company responds or if data appears.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.