meta The Fairlife Hackers Didn’t Need a Password. Anubis Leaked 1TB Anyway. | The Bullvine

The Fairlife Hackers Didn’t Need a Password. Anubis Leaked 1TB Anyway.

Coca-Cola refused to pay. Anubis published a terabyte anyway on July 27 — nine days after four US plants went dark. Your DairyComp goes down Monday, and 20 heats are gone by Wednesday.

EXECUTIVE SUMMARY: Anubis leaked a claimed 1TB of Fairlife data on July 27 after Coca-Cola refused to pay — the same day it finished recovering four US plants that had been down since July 16, which tells you backups fix downtime and nothing else. Security reporting points to CVE-2025-5777, “CitrixBleed 2,” a flaw that leaks live session tokens out of a Citrix appliance’s memory, so an attacker walks in as an already-logged-in user with no password to crack and no MFA prompt to answer. Nobody on the payroll had to click a thing, and the patch was free. Your DairyComp or PC-DART database, DelPro Remote, Lely T4C, and your daily co-op upload all live behind that same category of hardware — no vendor has disclosed a comparable flaw, but the connection type is identical. Price it on a 500-cow herd: 72 hours dark runs roughly $918–$982 in missed heats and re-keying using a deliberately low $1.50 per extra day open — below almost every published estimate — and $1,660–$2,590 once you load culling, with tighter repro herds losing more because more cows sit in the window. Dole booked $10.5M in direct costs in 2023 and JBS paid $11M in 2021, so the sector precedent is real even though Coca-Cola’s ransom figure was never disclosed. Two things before your next herd-check: turn on MFA anywhere an off-farm login runs on a password alone, and unplug one backup copy — then actually pull a file off it.

 Fairlife ransomware Anubis

Fairlife’s four US plants stopped running on July 16. Coca-Cola disclosed unauthorized third-party access to a portion of its systems, including production, and confirmed a ransomware event. Fairlife’s Canadian operations weren’t affected. The Anubis ransomware group listed Fairlife on its dark-web leak site on July 20, claiming it had locked servers and taken 1TB of confidential data, and gave the company a week. The deadline passed July 27 without payment. Anubis published the dataset.

One terabyte, now public. That volume is still the gang’s own claim — Coca-Cola hasn’t confirmed the amount or the contents, and Anubis never posted proof it was behind the breach.

Here’s the part worth your attention. Neither entry method researchers associate with this group requires an employee to click anything. The reported way in was a box on a rack. And boxes on racks are how your nutritionist pulls a ration, how your vet reviews a repro list from the truck, and how your herd data reaches your co-op.

The Reported Vector Is a Patching Story

Security reporting attributes the intrusion to CVE-2025-5777 — nicknamed “CitrixBleed 2,” a memory-read flaw in Citrix NetScaler ADC and Gateway appliances — and says Anubis went on to encrypt Fairlife’s Nutanix infrastructure. Coca-Cola hasn’t confirmed the vector publicly. Its own statement said the full scope, nature, and impacts were unknown.

The plain version of the flaw: an attacker sends a deliberately malformed request to a vulnerable box, and the box leaks live session tokens sitting in its memory. Those tokens are a hall pass belonging to somebody who already logged in properly. Replay the token, and you’re inside as a trusted user — no password to crack, no login screen, no second-factor prompt, because you never triggered the login.

Arctic Wolf’s research names two standard entry methods for this group: stolen VPN credentials, or CitrixBleed 2. Both are remote-access stories. Neither requires anybody on the payroll to do a single thing wrong.

And the fix for that particular flaw is free. Patch the appliance. Roger Grimes — the security veteran whose MFA numbers appear later in this piece — estimates better patching stops 20 to 40% of cybercrime, which is more than he credits MFA with. Every dollar figure below buys you something different: a smaller blast radius once somebody’s already inside. 

Why “Just Restore From Backup” May Not Save You

Anubis runs as ransomware-as-a-service. The core crew builds the tooling and rents it to affiliates who carry out the attacks — publicly active since roughly December 2024, rebranded from an earlier strain called Sphinx.

Double extortion is their baseline: encrypt the files, then publish whether or not anyone pays. Fairlife is now the textbook demonstration. The group offered to restore systems “within hours” if Coca-Cola paid — a sales pitch, not evidence. Coca-Cola declined, recovered production through its own procedures, and the data went out anyway.

But the feature that should change how you think about the external drive on your office shelf is an optional switch called /WIPEMODE. It permanently destroys file contents on top of encrypting them. Paying guarantees nothing. And a backup still plugged into your network when the attack runs can be destroyed alongside the original.

KPMG’s threat advisory documents the signature: files renamed with a .anubis extension, Volume Shadow Copies deleted through vssadmin before the ransom note ever appears. Prior confirmed victims span healthcare, construction, engineering, and hospitality across Australia, Canada, Peru, France, and the US. Fairlife is the most prominent victim publicly attributed to the group so far.

What Has a Food-Sector Attack Actually Cost?

While Anubis’s exact ransom figure remains undisclosed by either side, confirmed precedents demonstrate the scale involved when food supply chains freeze:

CompanyYearSectorDisclosed cost
Dole2023Produce/food processing$10.5 million in direct costs, including $4.8 million tied to continuing operations, after roughly half its legacy servers were hit
JBS2021Beef processing$11 million ransom paid in Bitcoin, even though most plants kept running

Neither figure predicts what Fairlife will report. Coca-Cola’s stated position in late July was that it doesn’t expect a material financial impact. The company reports quarterly, so any restated figure surfaces on its normal reporting calendar rather than in a press release. What was actually in that terabyte — customer records, employee files, supplier contracts, production specs — Coca-Cola still hasn’t said.

What Would Three Days Without Your Herd Software Cost You?

Here’s where a processor story becomes a barn story. Run it on a 500-cow herd: your DairyComp or PC-DART database goes unreachable Monday morning and stays down through Wednesday.

Semen is the cheap part. The expensive part is what a missed heat does downstream — those cows sit another 21 days before the next shot at them.

Now, what’s a day open actually worth? The published estimates don’t agree, and anyone who tells you there’s one number hasn’t read the literature. Plaizier’s review spanned −$0.29 to $2.60 per extra day open, with his own estimate landing near $3.36; French and Nebel modeled $0.42 at 100 days open climbing to $4.95 at 175 days open. De Vries’s separate work on pregnancy economics puts the average value of a new pregnancy at $278 and the average cost of a pregnancy loss at $555. 

We’re running $1.50 below. That sits under almost every published estimate on purpose — a conservative number you can’t argue with beats an aggressive one you can.

📊 Financial Breakdown: The 72-Hour Blackout on a 500-Cow Herd

Assumptions: 200 cows past voluntary waiting period (VWP) · 70% baseline detection rate, the floor for well-managed herds per AHDB and NADIS benchmarking · $1.50 per extra day open — our deliberately low anchor, below the published range, culling costs excluded · Assumes detection drops to zero without the due-list, so a crew catching heats visually will do better · 72 hours is under one full cycle, so no cow gets missed twice

  • Cows cycling in the window: 200 cows past VWP ÷ 21-day cycle × 3 days = ~28.6 cows
  • Missed heat loss: 28.6 × 70% detection = 20 heats you’d normally catch. Assume the database going down drops detection to zero on those cows: 20 × 21 extra days open × $1.50/day = $630. If your crew still catches a third of them on paper, it’s closer to $315.
  • Reconstruction labor: two days of somebody’s time (~16 hours, author estimate) @ $18–22/hr Cornell priced farm labor = $288–$352
  • Conservative total outage cost: $918–$982
  • Culling-inclusive model (NZ analysis, $3.19–$5.41/day open): $1,660–$2,590

The NZ figure uses a different currency and production system — directional only. Run $3.36 or $4.95 through the same arithmetic and the number climbs fast. Swap your own inputs through the days-open calculator.

What this model leaves out: delayed treatment calls, missed dry-off dates, and the milk-check reconciliation you can’t run against your own figures. It prices lost heats and re-keying. Nothing else.

Push the day-open cost into that culling-inclusive range and the same outage runs $1,660 to $2,590. Note what the spread tells you: a herd running a tight 21-day pregnancy rate loses more than a herd already carrying a long calving interval. That’s not a rounding difference. That’s the whole point of running it yourself.

Which of Your Systems Sit on That Same Kind of Connection?

Before the table: this is not a list of vulnerable products. No herd-software vendor — not VAS, not Lely, not DeLaval — has disclosed a flaw comparable to CitrixBleed 2, and no herd-management platform has been named as breached in this incident or any other. What follows maps where off-farm connections exist on a typical operation. Appearing on it reflects normal connected-system design, not a known weakness in any product.

SystemWhat it touchesWhere the off-farm connection lives
DairyComp 305 (VAS)Herd database, repro, production recordsRemote access and mobile sync create an external door by design
Lely T4CAstronaut robots, feeders, one shared networkLely publishes its own cybersecurity guidance precisely because the platform is network-connected
DeLaval DelPro / DelPro RemoteMilking data, off-farm accessDeLaval describes DelPro Remote as preconfigured network equipment with a built-in security package — a vendor-managed appliance sitting between your network and the outside world, the general category where the Fairlife flaw was found
PC-DART / BoviSyncDHI records, breeding decisionsSyncs outward to processors and DHIA
Milk-processor uploadsDaily production and component data pushed to your co-opA direct pipeline between farm and processor systems — the connection type that made Fairlife a supply-chain event
Sensor arraysRFID, activity monitors, parlor controlsOften bridged onto the office LAN unless somebody deliberately separated them — worth checking rather than assuming either way

Not a vulnerability list. No vendor named above has disclosed a flaw comparable to CitrixBleed 2.

The honest wrinkle: a vendor-managed remote-access box may well get patched faster than one you maintain yourself. Nobody outside your operation can tell you which situation you’re in. That’s why the last path below is a phone call, not a purchase.

Options and Trade-Offs for Farmers

Path 1: Enforce Multi-Factor Authentication (MFA)

  • Goal: Complete within 30 days.
  • Scope: Email, VPN, DelPro Remote, herd-management accounts, co-op portals.
  • A correction we owe you: In Part 1 we passed along CISA’s claim that MFA makes you 99% less likely to get hacked. That number doesn’t hold up, and we shouldn’t have repeated it without checking. 
  • The reality check: Roger A. Grimes, a 38-year security veteran and CISO advisor at KnowBe4, told Cybersecurity Ventures in February 2023 that MFA stops 30–50% of credential attacks — and that the 99% figure “is not true and never will be”. Grimes has also noted that 90–95% of MFA implementations can be bypassed with a well-built phishing email. Turn it on anyway. A third to a half of credential attacks is still the cheapest risk reduction available to you. 
  • What it won’t do: Stop a CitrixBleed 2 session-token replay. A stolen token skips the login entirely. This eliminates the low-hanging fruit, not the exploit that hit Fairlife.
  • Cost: $0 on systems you already pay for, up to $3–$15 per user per month for a paid tool plus a few hours of setup.
  • The friction: One hour of work, and complaints from whoever now types a code.

Path 2: Air-Gap One Backup (3-2-1 Rule)

  • Goal: Complete this month.
  • Action: 3 copies of your data, 2 different media types, 1 fully unplugged from any network.
  • Why it matters: Direct defense against Anubis’s /WIPEMODE switch, which permanently destroys file contents rather than just encrypting them.
  • Crucial step: Run a test restore onto a secondary laptop. An unverified backup is a hope with a schedule attached.
  • The limit: It protects your data, not your uptime — and nothing about a leak. Coca-Cola recovered production through its own procedures and still had files published.

Path 3: Segment Parlor Networks from Office Computers

  • Goal: Quarantine IT from OT (operational technology).
  • Action: Make sure the office laptop checking email cannot speak to your robotic milkers, feeders, or activity collars on a flat network.
  • What it won’t do: Stop a token-replay exploit. Patching would have, for free — and on Grimes’s own numbers, patching outperforms MFA. Segmentation buys containment, not prevention. 
  • Estimated investment: $2,000–$4,000 for a robotics or automated-feeding setup, from our earlier cybersecurity reporting drawn from composite accounts across multiple operations. Treat it as a benchmark, not a quote.
  • The basics, from the people who publish them: Penn State Extension’s farm cybersecurity guidance covers employee training, password management, timely software updates, phishing awareness, and regular backups. The 72-hour continuity plan and the 30–45 days of cash or credit for feed and payroll come from our own earlier reporting rather than from Extension directly — flagging that so you know which is which.
  • When to skip it: Two computers and a wall-mounted tablet don’t need segmentation.

Path 4: Ask Your Vendor Who Patches the Box

  • Goal: One phone call, no purchase.
  • The question: Who applies security patches to our connected gateway, on what schedule, and how would we find out if it were compromised?
  • Why this is the same fight: Deere spent years insisting owners didn’t hold rights to the software running their machines. It took an FTC settlement in July 2026 — plus 10 years of compliance oversight — to force diagnostic tools out to independent shops. Same argument as the tractor in your yard.
  • The signal to watch: Whether any herd-software vendor issues a security advisory in the wake of Fairlife. None has. If one does, this stopped being a processor story.
DefenseCostTimelineStops CitrixBleed-style token replay?
Enable MFA$0–$15/user/month30 daysNo — token replay skips login entirely
Air-gap one backup (3-2-1 rule)Minimal (existing drive)This monthNo — protects data, not disclosure
Segment parlor/office networks$2,000–$4,000Varies by setupNo — containment only, not prevention
Ask vendor who patches the box$0 (one phone call)ImmediateYes, if patch cadence is confirmed fast

Key Takeaways

  • If any account on your farm can be reached from off-farm with a password alone, turn on MFA before your next herd-check. It’s 30–50%, not 99% — and it still costs nothing on most systems you already pay for. 
  • If your appliance patching is behind, fix that first. Grimes puts patching at 20–40% of cybercrime stopped, ahead of MFA, and the CitrixBleed 2 patch was free. 
  • If you can’t remember your last successful restore test, treat that backup as unverified until you’ve pulled an actual file off it.
  • If you think good backups make you leak-proof, look again at Fairlife. Coca-Cola restored production, and the terabyte went public anyway. Backups fix downtime, not disclosure.
  • If your repro program is tight — service rate above 55%, conception above 32% — your outage cost runs higher than a herd carrying a long interval, because more cows sit in the window to lose.
  • If you want a number you can defend at the kitchen table, don’t use ours. The published cost of a day open runs from under a dollar to nearly $5 depending on days open and milk price. Ours is deliberately low. 
  • If your AMS, milk meters, and office computer share one flat network, get a segmentation quote and judge it against three days of lost records, not against the quote in isolation.
  • If a vendor manages your remote-access hardware, you don’t set the patch schedule. Find out who does and how fast they move.
  • If you’ve never written down what you’d do in the first 72 hours of an outage, that’s the cheapest gap on this list to close — University of Maryland Extension publishes a free farm business continuity template covering prevention, response, and recovery, and there’s a farm-specific cyber continuity guide that does the same. 
  • If somebody tells you paying fixes it, weigh Coca-Cola’s refusal against the $11 million JBS paid in 2021 while most of its plants kept running anyway. Neither is clean, and a /WIPEMODE victim who pays may get nothing back.

Coca-Cola has a security team, a legal department, and an incident-response retainer on standby. It still stopped production at four plants over a flaw in a piece of network hardware — and the patch for that flaw was free. So the question isn’t whether your operation is worth attacking. It’s whether you could name, right now, every device on your farm that something outside your fenceline can reach. Most producers get to three and go quiet. Where do you land?

Still unresolved: the ransom figure, what specifically was in the published dataset, how long production was actually down, and whether the National Milk Producers Federation or Cornell PRO-DAIRY will say anything on the record. Nobody has yet. The full outage model — sensitivity-tested across detection rates, days open, and herd size so you can run your own numbers instead of ours — is what we’re building next for the Bullvine Weekly.

📝 The 10-Minute Security Audit Checklist

  • [ ] Audit user access: Delete retired employees, former herd managers, or equipment reps granted access years ago.
  • [ ] Verify restore ability: Extract a single file from last week’s backup onto an offline machine. Did it work, or did the job just run?
  • [ ] Isolate remote login: Check whether any off-farm login relies solely on a single shared password — especially one also used for email.
  • [ ] Confirm appliance patching: Call your hardware or software vendor and ask: “Who applies security patches to our connected gateway, and how are we notified of vulnerabilities?”

Bullvine Tool: 72-Hour Outage Risk Calculator

Estimate what 3 days without your herd database or parlor network costs your operation.

Estimated 72-Hour Outage Impact

Cows Cycling in 3-Day Window: 28.6 cows
Missed Heat Financial Drag: $630.00
Reconstruction Labor Cost (16 hrs): $320.00

Total Direct Outage Cost: $950.00

*Calculations based on 21-day heat cycles, 16 hours of whiteboard reconstruction labor, and selected day-open economic benchmarks.

This article reflects public reporting and disclosures available as of July 30, 2026. Coca-Cola has not publicly confirmed the attack vector, the volume of data taken, its contents, or the duration of production downtime. Fairlife, Coca-Cola, and DeLaval had not issued public comment beyond the disclosures cited here as of publication. Correction: an earlier version of our July 18 coverage repeated CISA’s claim that MFA makes users 99% less likely to be hacked; that figure is disputed and has been corrected here.

Learn More

The Sunday Read Dairy Professionals Don’t Skip.

Every week, thousands of producers, breeders, and industry insiders open Bullvine Weekly for genetics insights, market shifts, and profit strategies they won’t find anywhere else. One email. Five minutes. Smarter decisions all week.

NewsSubscribe
First
Last
Consent
(T1, D1)
Send this to a friend