The reassuring sentence in Coca-Cola's statement is also the alarming one.
'Retail availability of Fairlife products has been largely unimpacted, due to the availability of existing inventory' [1].
Read that twice. Four US manufacturing plants making a brand with more than $3 billion in annual sales stopped producing for roughly eleven days after a ransomware attack, and the reason shoppers did not notice is that there was enough already made.
Inventory is not a security control. It is a buffer, and a buffer has a length.
The timeline is straightforward. Coca-Cola disclosed on July 16 that a third party had gained unauthorised access to Fairlife's technology systems and that US production had been halted. On July 27 the company said the majority of production had resumed across all four US facilities [1]. Canadian production was never affected.
The company says 'product quality and safety have not been impacted' [1] - the question a dairy customer asks first, and a fair thing to lead with.
It also confirms the attackers obtained certain data. It has not said what that data was, or whose [1].
No ransom payment has been disclosed. No group has been publicly named.
Coca-Cola bought full ownership of Fairlife from Select Milk Producers in 2020 in a deal valued at roughly $7 billion, and does not expect the incident to meaningfully affect sales [1].
That last point is almost certainly true at the scale of a company with 200 beverage brands. It is also why this kind of outage tends to leave no public record: the financial impact on the owner is negligible, the shelf impact was absorbed by stock, and the only party still carrying anything from it is whoever's data walked out.
Eleven days of buffer worked. The next one may be shorter.