Cybersecurity Wake-Up Call: Lessons from Fairlife's Ransomware Attack

Jul 22, 2026

Last week I learned that The Coca-Cola Company’s Fairlife division was the victim of a ransomware attack. This isn’t the first CPG company to have been hit by hackers — Clorox and Dole in 2023, Mondelez before that, etc. Yet, a successful attack on a company as large and sophisticated as Coca-Cola shows how brands and retailers large and small are increasingly at risk.

We don’t know any details about the attack, but Coca-Cola shared that Fairlife detected unauthorized access by a third party who gained access to systems connected to production operations.

Fairlife shut down affected systems and activated incident response protocols, and as a precaution, temporarily suspended U.S. production while systems are investigated and restored (Canadian operations were not affected).

Coca-Cola let me know that product quality and food safety were not impacted, that retailer data was not stolen, and that they believed there was sufficient inventory on-hand to ensure IGA stores were covered while they sort through the extent of the problem. Bravo to Coca-Cola and Fairlife executives for being upfront about the issue.

Many companies shut down operations even before they know the full extent of the intrusion because they cannot safely operate if they are unsure whether critical systems have been altered. That’s a smart decision, even if it causes supply chain disruptions in the short term.

Hackers often get into a company’s technology through phishing attempts, like getting employees to open and download a virus attached to an email. But these digital thieves increasingly sneak into suppliers’ and consultants’ systems first, which means that even a large and secure network is only as safe as the security of all of its partners.

For independent retailers, that must be a sobering thought. We are store operators, merchants, marketers, and not cybersecurity experts. It is hard enough to keep our own systems up to date and secure, much less worry about the security of all our technology and merchandise suppliers. IGA retailers’ loyalty systems, pricing and category management software, eCommerce providers, even marketplace partners like Instacart all connect and exchange data with key retailer POS.

When a major supplier like Fairlife, Clorox, or Dole get hacked, it’s a reminder that cyberattacks are no longer just IT problems — they can become manufacturing and supply-chain disruptions overnight.

For grocery retailers, the most important question is no longer, "Could a supplier be hacked?" The Fairlife incident shows that they can. The more important question is, "How secure are our own systems – and those of my key suppliers?"

Grocers know about risk. We already require suppliers to have insurance and food safety certifications, and we expect them to have product liability coverage.

Cybersecurity should increasingly be viewed the same way.

This is especially important with smaller, local suppliers (farmers, growers, producers) who may not be as sophisticated as national brands. Have you asked your suppliers these questions?

  • Do you have a cybersecurity program?
  • Who is responsible for cybersecurity?
  • Do you perform annual security assessments?
  • Do you have a documented incident response plan?
  • Do you conduct employee security training?
  • And most importantly, do you carry cyber security insurance?

Insurers increasingly require security controls before issuing coverage. While insurance doesn't guarantee security, it often indicates a minimum level of cyber maturity.

You don't need the technical details but you do need confidence that all your partners take the issue seriously. Of course, you need to ask yourself the same questions.

IGA offers a free cybersecurity audit. Click here to learn more about evaluating your own cybersecurity risks and to learn what you need to do to harden your own systems.

The reality is that most retailers need spend very little – a new server, updated software, and cybersecurity training can all massively reduce your risk. And of course IGA offers cybersecurity training modules, a security best practice assessment, and a security best practice guide for free

Big company or small; global, national, or local, we are all at risk. Take a moment to evaluate your risks and ensure all your suppliers know you hold them to the same standards. We can’t inoculate ourselves fully but a few simple steps upfront can help you radically reduce the risk of a successful attack – and prepare you in the event one happens. And asking the right questions of your partners both arms you with confidence they are taking cyber security risk seriously, but also helping smaller companies to be aware they need to upgrade their efforts.

Subscribe by Email

No Comments Yet

Let us know what you think