Cybersecurity Fairlife Hack Shows: IT Vulnerabilities Are Becoming an OT Risk

Source: TX One Networks | Translated by AI 2 min Reading Time

Related Vendors

Ransomware hits production: The attack on Coca-Cola subsidiary Fairlife brought the entire US manufacturing to a halt in July 2026. TX One analyzes how attackers penetrate OT from IT—and why traditional firewalls are no longer sufficient to effectively protect production facilities.

One click, one shutdown: How ransomware paralyzed Fairlife's factory.(Source:   /  Pixabay)
One click, one shutdown: How ransomware paralyzed Fairlife's factory.
(Source: / Pixabay)

In mid-July 2026, Fairlife, a dairy subsidiary of Coca-Cola, fell victim to a ransomware attack by the Anubis group. The consequences: U.S. production had to be temporarily completely halted, and the attackers reportedly exfiltrated around 1 terabyte of company data. Coca-Cola confirmed the incident in an SEC filing and immediately activated incident response measures. There is no official confirmation yet regarding the exact technical details of the attack method.

A Known Attack Pattern

Even though the exact attack chain at Fairlife has not yet been publicly confirmed, the case follows a now familiar pattern: IT as the entry point, OT as the actual target.
Ransomware groups like Anubis, which operate under the Ransomware-as-a-Service (RaaS) model, typically proceed in a collaborative manner:

  • Entry: compromised credentials, phishing, or unpatched vulnerabilities in publicly accessible systems (e.g., VPN gateways).
  • Lateral movement: Expansion of privileges within the IT network.
  • Jump to OT: Exploitation of historically developed, often poorly documented IT-OT connections—or unmanaged USB devices as an entry point.

Why OT is the Actual Target

Once attackers reach operational technology, the attack logic shifts: while data protection is the primary focus in IT, availability and physical safety are paramount in OT. The manipulation or encryption of PLCs, HMIs, or SCADA systems directly results in production downtime—and thus significantly higher economic pressure than with pure data theft.

The Lesson for Practice: OT-Native Zero-Trust Strategies

From my perspective, the Fairlife case exemplifies why the classic separation of IT and OT security is no longer sufficient. Three key approaches:

  • Segmentation down to the equipment level—Protection not only at the IT-OT boundary but also down to the individual machine and network communication
  • Deep protocol understanding—Solutions that recognize proprietary industrial protocols and block anomalies in real time before they reach control systems
  • OT-appropriate endpoint protection—specifically for legacy systems without available patches, with low resource requirements and ICS packet awareness instead of traditional signature updates

Only a consistent, OT-native zero-trust approach with granular segmentation and continuous monitoring of industrial data traffic can prevent an IT vulnerability from causing a production shutdown—rather than having to conduct costly, reactive incident response processes afterward.

Subscribe to the newsletter now

Don't Miss out on Our Best Content

By clicking on „Subscribe to Newsletter“ I agree to the processing and use of my data according to the consent form (please expand for details) and accept the Terms of Use. For more information, please see our Privacy Policy. The consent declaration relates, among other things, to the sending of editorial newsletters by email and to data matching for marketing purposes with selected advertising partners (e.g., LinkedIn, Google, Meta)

Unfold for details of your consent