Ransomware coverage often centers on stolen data and leaked files. A recent incident is a reminder that the more immediate cost can be operational. In July, Coca-Cola disclosed in a securities filing that its Fairlife dairy subsidiary had been breached, with attackers reaching parts of the environment tied to production. The company suspended US manufacturing while Canadian operations continued, and the Anubis ransomware group later listed Fairlife on its leak site.
Coca-Cola stated that product safety and quality were not affected, and the company activated its incident response plan, engaged outside advisors, and notified law enforcement. The response followed established practice. The disruption still happened, because the systems attackers reached were connected closely enough to production to force a shutdown.
Manufacturing and production environments increasingly run on networked systems: scheduling software, quality control platforms, and equipment connected for monitoring and automation. These systems improve efficiency, but they also create a path between office networks and the physical processes that keep a facility running.
Ransomware groups have learned that halting production creates urgency that data theft alone does not. A company can sometimes absorb a data breach and continue operating while managing the fallout. A company cannot easily absorb a halted production line, which makes manufacturing environments a higher-pressure target for extortion.
The core issue in incidents like this is usually not whether a breach occurred, but how far attackers could travel once inside. A well segmented network limits an intrusion in the corporate IT environment from reaching operational technology systems that control physical processes. A flat network, where office systems and production systems share the same trust zone, allows a single compromised account to become a plant-wide shutdown.
Companies expanding manufacturing or logistics operations into the US often inherit network designs built for convenience during setup, with segmentation treated as a later project rather than a foundational requirement. That sequencing creates exposure during exactly the period when a new facility is least prepared to detect and contain an intrusion.
Separate operational technology networks from corporate IT networks as a baseline requirement, not an optional upgrade. Production equipment, scheduling systems, and quality control platforms should not sit on the same network as email and general office systems.
Identify which systems, if compromised, could force a production stoppage. This list is often smaller than expected and gives a clear priority order for security investment.
Build a business continuity plan specific to production disruption, separate from a general incident response plan. Losing IT systems and losing the ability to manufacture product create different operational demands, and the plan should reflect that difference.
Test backup and recovery specifically for production-critical systems. A backup strategy built around office data does not necessarily cover the specialized systems that run a manufacturing floor.
Coordinate incident response planning between IT security and operations leadership before an incident occurs. The decision to halt production is not a security decision alone, and the people with the authority to make that call need to be part of the planning process in advance.
The Fairlife incident shows that the value at risk in a breach is not always data. For companies with any physical production or logistics component, the ability to keep operating can be the primary asset attackers are counting on being able to disrupt. Segmentation and continuity planning built specifically around that risk matter as much as the more familiar defenses aimed at data protection.