When Production Stops Anyway

   Jul 21, 2026 | Adam Fearn, Senior OT Architect, Radiflow
What the Fairlife Ransomware Attack Reveals About Cyber Risk in Food & Beverage Manufacturing

On 16th July, The Coca-Cola Company disclosed that its dairy subsidiary Fairlife had detected
unauthorised access to a portion of its systems, including production-related systems, in
connection with a ransomware attack. Production across Fairlife’s US operations was
temporarily suspended. Canadian operations were not affected, product quality and safety were
reported as unimpacted, and at the time of writing no group has claimed responsibility and the
full scope of the incident is still being investigated.

Most of the coverage has treated this as another entry in a growing list of attacks on
manufacturers. But there is a detail in this story that deserves more attention than it’s received,
because it says something important about how cyber risk actually works in food and beverage
production.

There is no public confirmation that the attackers reached the OT network. And production
stopped anyway.

You don’t have to touch the plant to stop the plant

For people who haven’t worked inside a food manufacturing operation, this can seem puzzling.
If the control systems weren’t confirmed as compromised, why stop production at all?
Anyone who has run a plant knows the answer. Modern food and beverage production doesn’t
run on control systems alone. It runs on an interconnected web of scheduling, recipe
management, quality release, traceability, labelling, and logistics systems. The production line
may be perfectly capable of filling bottles, but if you can’t trust the systems that tell you what to
make, verify what went into it, release it against your quality standards, and prove where every
batch went, you cannot responsibly make food.

In a regulated food environment, traceability isn’t paperwork. It’s the thing that stands between a
routine production day and a national recall. If a ransomware incident casts doubt on the
integrity of those records, or simply takes them offline, stopping production is the only defensible
decision available. The shutdown is unrelated to evidence that the attackers reached the OT
network. It’s evidence of how deeply food production depends on traceability and trust.

Why food and beverage is a harder place to have a bad day

Food manufacturing carries burdens that most other sectors don’t, and they compound quickly
during a cyber incident. The inputs are perishable and they keep coming. A dairy can’t pause its
raw material supply the way a metal fabricator can. Milk arrives on a schedule set by biology,
not by your incident response plan. Every hour of downtime creates decisions about raw
materials that are aging in silos and tankers, and those decisions have costs whether you make
them well or badly.

The outputs are perishable too. Finished product has a shelf life, retailers have delivery
windows, and shelf gaps are visible to the public within days. Previous incidents in the sector
have shown how quickly a production disruption results in empty shelves, and how long the
commercial memory of that lasts with retail customers.
And the whole operation sits under a food safety regime that, rightly, does not flex for cyber
incidents. Cleaning cycles, quality holds, batch release and allergen controls all have to be
demonstrably intact before lines restart. Recovery in food and beverage isn’t finished when the
IT team restores the servers. Recovery only starts when quality and food safety teams can
stand behind the product again, and that is a longer and more careful road.

The uncomfortable question for every F&B operator

The lesson from Fairlife is not primarily about ransomware defence, important though that is. It’s
about interdependence. Most food and beverage manufacturers could not draw an accurate
map of which systems their production actually depends on, where those systems connect to
the plant floor, and what would still be able to run, safely and legally, if the IT estate went dark
tomorrow. That map matters in both directions. It tells you how an IT incident becomes a production
incident, which is what appears to have happened here.

And it tells you how an intruder who starts in IT could move toward the systems that matter most, which is the scenario every OT security programme exists to prevent. Whatever the cause, the US/Canada split is a useful illustration of the underlying point. Segmentation and separation, done well, buy you options in exactly these moments.

Three questions are worth asking inside any food and beverage business this week.
1. Do we know, specifically, which IT systems our production cannot run without, and have we tested that assumption rather than inherited it?

2. Do we have genuine visibility into what is on our plant
networks and how they connect to everything else?

3. And if we had to make the stop-or-continue decision Fairlife faced, could we make it based on evidence about our own environment, or would we have to stop production because we simply don’t know?

That last distinction is the one that separates a controlled pause from a crisis. Organisations
with real visibility into their operational environment can scope an incident, contain it, and make
restart decisions with confidence. Organisations without it are left with the precautionary
shutdown as their only safe move, for as long as the uncertainty lasts. Both organisations stop
the line. Only one of them knows when it’s safe to start it again.

Closing Summary

Building that kind of visibility, and the segmentation to act on it, is the everyday work of OT
security, and it’s the problem Radiflow spends its time helping food and beverage manufacturers
solve, well before an incident forces the question.
The details of the Fairlife incident will emerge in time, and conclusions about what happened
there should wait for them. But the structural lesson doesn’t need to wait. In food and beverage
manufacturing, production availability rests on far more than the control systems, and defending
it starts with knowing exactly what it rests on.

Additional Resources

Request Demo Contact Us