What the Fairlife Dairy hack can mean to cybersecurity for food and drink
On July 16, 2026, Coca-Cola’s Fairlife Dairy unit suffered a cyberattack shutting down domestic operations. The next day, Food Processing magazine (a Control partner publication) wrote an article about this incident. In preparation for the article, I was contacted by the author, Dave Fusaro, about my thoughts. I sent him my blog about not addressing the real problem – the cybersecurity of equipment.
Dave’s article stated that the company “suffered a cyberattack affecting production-related systems, forcing a suspension of all its U.S. manufacturing. Product safety was not impacted, and the company has not disclosed whether data was stolen or what kind of a ransom was demanded, although the parent firm called it a ransomware attack.” Dave’s article addresses the network focus by Claroty and an insurance company, which is relevant if it were a ransomware attack. My perspective is focused on the impact of production-related systems. It is possible this case has both.
The recently released Publicly Available Specification (PAS) 96:2026 provides guidelines for protecting food and drink from deliberate threats using a structured approach to risk management known as Threat Assessment Critical Control Points. It aims to enhance food safety and supply chain security against intentional acts. PAS 96:2026 has been extended to address IT and OT cyber threats via Annex C- Cyber Vulnerability.
Get your subscription to Control's tri-weekly newsletter.
Fairlife is not an isolated case in food and drink manufacturing, as there have been many ransomware cases (for example, with JBS Foods) as well as approximately 50 control system cyber incidents, not all of which were malicious but still caused harm. Understanding and learning from incidents like the recent Fairlife case and addressing these cases can help improve the guidance in PAS 96 within a food protection lens to ensure the public’s health, well-being and trust are being maintained.
On July 21, 2026, the Sacramento and San Francisco InfraGard Members Alliances held their 4th Annual Food and Agriculture Symposium. Domestic terrorism and general agriculture threats were on the agenda. Cybersecurity was not explicitly addressed. The food and agriculture sectors need to adequately address network and control system cybersecurity to protect our food supply as described in PAS 96:2026.
About the Author
Joe Weiss
Cybersecurity Contributor
Joe Weiss P.E., CISM, is managing partner of Applied Control Solutions, LLC, in Cupertino, CA. Formerly of KEMA and EPRI, Joe is an international authority on cybersecurity. You can contact him at [email protected]

