The Coca-Cola Company confirmed on July 27 that the ransomware attack against its fairlife dairy subsidiary involved the taking of data, not just disruption to production systems, according to a press release on fairlife’s newsroom. The update follows Coca-Cola’s July 16 disclosure that a third party had gained unauthorized access to fairlife’s production-related systems, which halted output at all four US fairlife facilities. Coca-Cola now says fairlife has resumed the majority of production and that product quality and safety have not been impacted, while stopping short of specifying what data was taken, how many people are affected, or which systems were exposed.

The confirmation matters less for what it reveals than for what it still withholds. Companies increasingly separate the operational disclosure, that systems were hit and production stopped, from the data disclosure, what was actually taken, and the gap between the two, eleven days in this case, is becoming routine for ransomware events that touch manufacturing systems, which CyberTech covered when the production halt was first disclosed.

The detail security leaders should register is the materiality language: Coca-Cola states the incident is not reasonably likely to have a material impact on its financial results, a judgment that effectively closes the loop on further disclosure escalation unless new facts emerge. For risk teams tracking vendor and subsidiary exposure in food and beverage manufacturing, the operative lesson is that a resumed production line and a confirmed data theft are two different claims, and this event shows a company can state the first firmly while taking eleven days to confirm the second at all.

Source: fairlife