fairlife temporarily halts production following unauthorised access
Coca-Cola reported that fairlife had temporarily suspended production operations in the United States after detecting unauthorised access to part of its systems, including systems related to production.

News summary
Coca-Cola reported that fairlife had temporarily suspended production operations in the United States after detecting unauthorised access to part of its systems, including systems related to production.
In industry, cybersecurity and operations are interconnected. Segmenting plant networks and having offline restoration reduces the probability of a digital intrusion affecting production.
Source: Reuters — 27 July 2026
What happened
According to Reuters, Coca-Cola reported that fairlife, its dairy brand, had temporarily suspended production operations in the United States after detecting unauthorised access to part of its systems, including production-related systems.
The company did not publicly detail the origin of the access or the exact scope of the affected systems. What matters in this case is the decision: halting production as a precaution while the investigation took place, rather than continuing to operate on systems whose integrity could not be guaranteed.
What it teaches an industrial business
In a plant, downtime is not only caused by encrypted files. It is enough for the business to lose confidence in the systems that plan, dose, label or record traceability for production to stop being safe, especially in food, where a batch error has health and commercial consequences.
For a mid-sized business in Catalonia with its own plant, the useful question is not whether it could suffer unauthorised access, but how much of the plant network is exposed when it happens on the office network, and how long it would take to resume production with confidence. If both networks are connected without separation, an administrative incident can turn into a line stoppage.
What to review
Four practical checks to reduce the impact of a similar case:
- Segmentation between the office network and the plant network, with access between them limited and logged.
- Offline backups of production and traceability systems, with restore tests.
- Criteria agreed in advance for deciding when to stop a line and who makes that decision.
- A procedure for resuming production that validates the integrity of recipes, configurations and records.
Frequently Asked Questions
- Why would a company stop production if the attack hasn't encrypted anything?
- Because if it cannot verify the integrity of its production and traceability systems, continuing to manufacture creates quality, food safety and incident-spread risks.
- What does segmenting the plant network mean?
- Separating the network of industrial equipment from the office network and controlling which communications are allowed between them, so a compromise in one does not directly reach the other.
- Do backups also work for industrial systems?
- Yes, provided they include configurations, recipes and traceability databases, are kept offline and have been tested to confirm they can be restored.
Concepts mentioned in this article: Cybersecurity
Is your company prepared for an incident of this type? At Seintec we can review access, backups, cloud, endpoints and procedures to reduce exposure and recovery times. Let’s talk.
Contact SeintecRelated service
Cybersecurity
We shield your business so it never stops.