A ransomware attack temporarily halted U.S. production at Fairlife, Coca-Cola’s Chicago-based dairy subsidiary, after hackers breached systems connected to manufacturing operations. Fairlife makes ultra-filtered milk, protein shakes and other dairy drinks.
Coca-Cola disclosed the incident July 16, saying an unauthorized third party had accessed Fairlife systems, including production-related systems. The company activated its incident-response and business-continuity plans, brought in outside cybersecurity specialists and notified law enforcement. Canadian production continued, and product quality and safety were not affected.
The Anubis ransomware group later claimed responsibility, alleging it encrypted Fairlife’s Nutanix systems and stole 1 terabyte of data. Coca-Cola confirmed data was taken and said most U.S. production had resumed, but it has not verified Anubis’ role, the volume of stolen data or the initial access method.
Security professionals should not assume that systems were stopped because ransomware directly encrypted programmable logic controllers or other operational technology (OT). Production can stop because essential IT services fail or operators cannot verify that manufacturing systems and their associated data remain safe. Worker and customer safety are always of primary concern in the OT world. Increasingly, so is the data that OT systems generate.
Map the dependencies that keep production running - And how to reveal risks
Manufacturing environments depend on far more than plant-floor equipment. That's just the tip of the iceberg, in many cases. Authentication, network time, file storage, virtualization, enterprise resource planning, production schedules and quality systems can all become critical dependencies to consider.
“Across hundreds of ransomware recoveries, the number of times I’ve seen industrial systems encrypted is a rounding error,” says Jeff Liford, associate director at cyber disaster recovery firm Fenix24.
Production usually stops because a central IT dependency was disrupted or because systems were taken offline during containment, he explains.
Security professionals need to map application and infrastructure dependencies across IT and OT. Static network diagrams may omit administrative connections, temporary firewall rules and recently added services.
Packet captures, network-flow analysis and application telemetry can reveal what a production line communicates with during a shift. Teams should identify required authentication requests, file shares, database connections, remote-management sessions and cross-site services.
Dependency maps must also expose concentration risk. A single Active Directory environment, hypervisor cluster, ERP platform, quality-management system or backup repository supporting multiple plants can expand the blast radius of one compromise.
“Shared services are a blast radius decision masquerading as an efficiency decision,” Liford says.
Make IT/OT segmentation verifiable - Focus on identity and segmentation
Fairlife has not disclosed how attackers initially gained access. Across manufacturing attacks, however, compromised credentials and inadequately secured remote-access services are common entry points.
“The entry point in most of these incidents is identity. Ransomware operators don’t force their way in. They walk in with credentials that look legitimate,” says Shane Barney, CISO at Keeper Security.
Corporate and OT environments should not share administrative credentials or unrestricted trust relationships. Privileged OT access should use separate accounts, phishing-resistant multifactor authentication and a hardened jump server in a demilitarized zone. Sessions should be recorded, access should be time-limited and permissions should follow least-privilege principles.
Network boundaries should deny traffic by default and permit only documented operational requirements. Lateral-movement protocols such as SMB, RDP and WMI require particular scrutiny at IT/OT boundaries.
Configuration analysis is as important as architecture. Firewall rules created for vendors, maintenance or troubleshooting can quietly remain active for years.
“Most segmentation exists on the network diagram, but not in the rule base,” Liford says.
Professionals should inspect firewall configurations, capture cross-boundary traffic and test whether enforcement matches the documented architecture. Disconnecting a plant from corporate IT for a defined period can reveal whether production is genuinely resilient or depends on services outside the OT boundary.
Industrial systems may also remain operational long after their original security assumptions have become obsolete. Teams need the skills to assess legacy assets, apply compensating controls and monitor equipment that cannot be patched or replaced immediately.
“Legacy best practices may not be up to the task of mitigating current threats, or worse, those that might be deployed in the coming years,” says Tim Mackey, head of software supply chain risk strategy at Black Duck.
Detect movement before ransomware reaches shared infrastructure
Detection programs should monitor the pathways ransomware operators use after initial access, including unusual authentication, privilege escalation, remote-administration activity, security-control changes and attempts to reach hypervisors or backup infrastructure.
Encrypting a hypervisor can disable numerous workloads simultaneously. A centralized backup platform creates similar risk because compromising one administrative plane can undermine recovery across multiple sites.
Security teams must correlate identity, endpoint, network and virtualization telemetry to identify behavior that may appear legitimate when viewed in isolation. They should also continuously review third-party access and give equipment vendors narrowly scoped accounts through the same controlled pathway used by internal administrators.
“Security must be practiced as a multidisciplinary and companywide effort, and companies must adopt the same rigorous guardrails when hiring outside vendors as they do for internal personnel,” says Matthieu Chan Tsin, senior vice president of resiliency services at Cowbell.
Restore the process, not just the servers and systems
Recovery begins with forensic triage. Responders must determine whether systems are encrypted, partially damaged or recoverable before deleting data or launching large-scale restores. They must also verify that backup data, catalogs and management applications survived.
“Immutable backups are frequently less immutable than the sales brochure claimed,” Liford says.
Recovery requires systems-engineering skills such as examining disk structures, restoring virtual machines, rebuilding Active Directory, rotating compromised credentials and cryptographic material, and sequencing interconnected services. Backup copies should reside on genuinely separate systems rather than one platform holding multiple replicas.
Manufacturing recovery also requires plant-specific knowledge. Restoring a server does not establish that production can resume safely. Plant engineers and process owners must validate configurations, product recipes, sanitation controls, quality systems and release procedures.
“Unlike a typical corporate network, manufacturing environments can’t simply be restored from backup and brought back online. Resuming operations safely means validating process integrity, not just IT systems,” Barney says.
The meaning of OT system recovery
Cyber responders must work with operations, quality, safety and business-continuity teams instead of treating technical restoration as the final objective.
“IT can declare a system healthy, but the process owner is the only person who can certify the business function,” Liford says.
The Fairlife incident highlights how ransomware can halt physical. As IT and OT become more interconnected, defenders must understand production dependencies, segmentation, identity controls and the operational validation required before systems can safely resume.
CompTIA SecOT+ is designed to build and validate those capabilities across manufacturing and other industrial environments. Review the draft objectives and register for updates ahead of its December 2026 release.