Coca-Cola and Chick-fil-A data breaches spark lawsuits

Major US brands face lawsuits after data breaches

Coca-Cola and Chick-fil-A Data Breaches: What Happened?

Recent cyber attacks on Coca-Cola’s Fairlife subsidiary and Chick-fil-A have resulted in significant data breaches, operational disruption and swift legal action in the United States. The Coca-Cola and Chick-fil-A data breaches highlight the growing risks of ransomware and credential stuffing, with consequences ranging from business interruption to customer lawsuits.

Coca-Cola/Fairlife: Ransomware Hits Production

On 16 July 2026, Coca-Cola disclosed that its US dairy business, Fairlife, experienced a ransomware incident. Attackers gained unauthorised access to parts of Fairlife’s IT and production-related systems, prompting a temporary shutdown of US production facilities while incident response and business continuity plans were activated.

A ransomware group calling itself Anubis claimed responsibility via a Tor leak site. The group stated it had exfiltrated up to 1 TB of data and threatened to release it unless negotiations took place by 27 July. Publicly posted samples included purported Fairlife employee records. Despite these threats, Coca-Cola confirmed only the theft of “certain data” and maintained that product quality and safety were not compromised.

  • 16 July 2026: Coca-Cola files an SEC Form 8-K, revealing unauthorised access and production suspension at Fairlife.
  • 20-21 July 2026: Anubis lists Fairlife on its leak site, threatening to publish stolen data.
  • 28 July 2026: Coca-Cola confirms data theft; most US production resumes.

The exact method of initial compromise and malware used have not been publicly detailed. As of early August, neither indicators of compromise nor specific technical details have been released.

Chick-fil-A: Credential Stuffing Targets Customer Accounts

Chick-fil-A suffered a separate but equally impactful incident. Between 17 and 19 June 2026, attackers launched a large-scale credential stuffing campaign against the company’s website and mobile application. By using credentials obtained from unrelated third-party breaches, attackers gained access to a limited set of Chick-fil-A One loyalty accounts.

Potentially exposed information included customer names, emails, loyalty membership numbers, mobile pay numbers and QR codes, the last four digits of stored cards, account credit balances, and, if provided, birthdays, phone numbers and addresses. Chick-fil-A responded by forcibly logging out affected users, removing stored payment methods, resetting passwords, restoring account balances and notifying those impacted.

  • 17-19 June 2026: Automated credential stuffing campaign targets Chick-fil-A.
  • 13 July 2026: Chick-fil-A determines which customers were affected.
  • 20 July 2026: Official breach notification filed with the Massachusetts Attorney General.
  • 22 July 2026: Media reports emerge on the breach and affected states.

At least 13,000 individuals were impacted, according to state filings. There is no evidence that attackers exploited a software vulnerability; instead, they capitalised on customers’ use of recycled passwords from prior breaches. The company did not release technical indicators or specifics on the tools used.

Litigation and Legal Fallout from the Data Breaches

The rapid emergence of class-action litigation underscores the seriousness of these incidents. In late July 2026, federal lawsuits were filed in Atlanta against both Coca-Cola/Fairlife and Chick-fil-A. The suit against Fairlife, brought by a former employee, alleges failure to adequately protect sensitive data such as names and Social Security numbers. A separate class action against Chick-fil-A, filed by a customer in Texas on 23 July, alleges insufficient security for loyalty account data.

These lawsuits reflect a growing trend: organisations face not only operational and reputational risks from cyber attacks but also substantial legal exposure. According to public filings, both companies have engaged law enforcement and regulatory authorities, and have issued multiple public and regulatory disclosures since the incidents.

Technical Analysis: Attack Methods and Remediation

Ransomware Impact on Fairlife Production

The attack on Fairlife involved a ransomware payload that allowed threat actors to access and potentially encrypt production-related systems. The Anubis group’s public claims about the volume and sensitivity of stolen data remain unverified by Coca-Cola, which has only confirmed the loss of some data. The incident caused a temporary halt in production, highlighting the operational risk posed when attackers gain access to core business systems beyond the corporate IT network.

Credential Stuffing and Account Takeover at Chick-fil-A

Chick-fil-A was targeted by automated bots attempting to log in using credentials harvested from unrelated breaches. Where successful, attackers accessed customer loyalty accounts and could view or misuse stored information. The company’s response included:

  • Forced logouts for affected accounts
  • Removal of stored payment methods
  • Mandatory password resets
  • Restoration of loyalty credits
  • Customer notification and advice on account security

The attack demonstrates the persistent threat posed by credential reuse and the importance of protecting customer-facing applications with multi-factor authentication (MFA) and detection controls for automated abuse.

Why These Data Breaches Matter

These incidents highlight two escalating risks for all organisations: the operational impact and data theft potential of ransomware that can reach production networks, and the growing exposure to account takeover attacks through credential stuffing. The swift move from incident disclosure to class-action lawsuits also signals intensifying legal risks, including regulatory scrutiny and group litigation, that organisations must anticipate and prepare for.

What Organisations Should Do Next

While these cases are US-based, the lessons apply broadly. Organisations should:

  • Review segmentation and backup strategies for production and critical business systems to limit ransomware impact.
  • Enforce MFA and implement rate-limiting or bot protection on customer portals to mitigate credential stuffing risks.
  • Prepare incident response plans that address both technical and legal consequences, including timely disclosure and customer notification.

Rapid and decisive action, both technical and legal, is crucial to managing fallout and maintaining trust when data breaches occur.

Originally reported by AJC.com.

Share this bulletin

About the Author

Rob McBride Headshot - CyPro Partner and leading cyber security expert

Rob McBride

Partner

  • CISSP
  • ACA Chartered Accountant
  • MPhil
  • BSc
  • SOC 2
  • ISO 27001

Rob McBride

Rob is a Founding Partner at CyPro and a highly experienced CISO. Beginning his career with a successful tenure at Deloitte, Rob has since amassed a wealth of experience, notably serving as a cyber security advisor to the UK government and spearheading cloud security transformations for several global banks.

At CyPro, Rob leads the managed service business line, working extensively across multiple sectors including telecommunications, technology, higher education, travel, and retail. He is passionate about equipping small and medium-sized businesses (SMBs) with robust cyber security strategies to fuel their growth.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call