AYush Chhabra

The Risk Gap

Perspectives on risk, security, and decisions that matter

Ransomware Attack Halts Coca-Cola’s Fairlife Dairy Production

Coca-Cola halted production across its U.S. Fairlife dairy facilities this week after a ransomware attack — a type of intrusion where criminals lock up a company’s computer systems and demand payment to unlock them. The products were fine. The milk was safe. But the machines that schedule, track, and coordinate the making of it were compromised enough that the company chose to stop rather than push forward. That choice is the interesting part.

Fairlife is not a sleepy side project. It crossed a billion dollars in annual sales, and Coca-Cola has been pouring money into it — a $650 million plant expansion in Michigan, a new 745,000-square-foot facility in New York. When a business grows that fast, the physical side races ahead: more tanks, more lines, more trucks. The digital plumbing underneath tends to get bolted on as you go, not rebuilt. Systems that were adequate for a joint venture get stretched to cover a billion-dollar operation, and nobody stops the expansion to ask whether the security kept pace with the concrete.

That’s the tradeoff hiding here. Growth is visible and rewarded. Security debt is invisible until the day it isn’t. A leadership team deciding where to put the next dollar will almost always choose the plant that makes more milk over hardening the systems that already seem to work. It’s not negligence. It’s how incentives point. The plant expansion shows up in earnings. The network segmentation project shows up nowhere, until it’s the reason you didn’t have to shut down.

There’s a second decision worth noticing, and this one Coca-Cola seems to have gotten right. A researcher quoted on the broader trend made the key point: attackers increasingly aren’t hunting for Coca-Cola specifically. They scan the internet for exposed, vulnerable systems at machine speed and figure out who the victim is only after they’re already inside. Being a food company didn’t make Fairlife a target. Having an internet-facing weakness did. That reframes the whole question. You’re not defending against someone who wants your milk. You’re defending against a machine that pings every door on the internet and walks through whichever ones are unlocked.

Given that, halting production was the sober move. When you can’t yet tell how far an intruder reached, running your systems anyway means potentially spreading the problem or making decisions on data you can’t trust. Stopping is expensive and embarrassing, but it’s the choice of an organization that would rather eat a known cost than gamble on an unknown one. The food and agriculture sector has absorbed roughly 205 such attacks this year — the ones that stay down longest are usually the ones that kept running when they should have paused.

The thing worth sitting with: in your own environment, the systems that grew fastest are the ones most likely to have outrun their own defenses. Ask which part of your operation expanded so quickly that nobody circled back to check whether the locks still fit the doors.

Leave a Reply

Your email address will not be published. Required fields are marked *