Coca-Cola told the SEC on July 16 that it had shut down all US production at Fairlife, its roughly $4 billion dairy brand, after a ransomware attack. Canadian production kept running. The company gave no timeline for restarting and did not name the attackers. The word in the filing that should hold a board's attention is "suspended." A ransomware attack, the kind of event most executives still file under "IT problem," stopped a physical production line at one of the largest beverage companies in the world.
In a ransomware attack, your security team's one reliable advantage is time. The intruder breaks in, then works for hours, sometimes days or weeks, looking around, moving sideways, hunting for what matters, and somewhere in that window your monitoring is supposed to catch them. A report published July 1 shows that window closing.
The price of cyber insurance is falling, and the cheaper it gets, the easier it becomes to mistake a policy for protection. A cyber claim is denied far more often than most buyers expect, and a soft market widens the gap between having coverage and being protected.
Two cybersecurity professionals hired to defend companies against ransomware were running it against them instead. On April 30, Ryan Goldberg, a former incident response manager at Sygnia, and Kevin Martin, a former ransomware negotiator at DigitalMint, were each sentenced to four years in federal prison for deploying BlackCat ransomware against multiple US victims during a six-month spree in 2023.