Breaking Down the Coca-Cola/Fairlife Hack

Updates and takeaways from manufacturing’s most recent high-profile ransomware attack.

Anubis Azhartz
istock.com/azhartz

In early July, hackers were able to penetrate the defenses of Coca-Cola subsidiary Fairlife. The extent of the attack was initially unclear, but concerning enough that the company halted all U.S. operations for more than a week. With downtime equating to death in manufacturing, and especially the food processing sector, this shutdown led to widespread concern about the depth of the compromise.

Coca-Cola has been consistent in assuring the public that the attack had no ill effect on the company, its products or employees. However, it did admit that the attackers gained unauthorized access to a portion of Fairlife's production systems, which triggered the shutdown.

More details emerged last week, with ransomware-as-a-service (RaaS) group Anubis taking credit for the hack. The group stated it was able to lock down servers and encrypt 1TB of data, which they’ve also threatened to leak if their ransom demands are not met. The nature of the stolen information has not been disclosed. Also, as of press time, there was no record of either a ransom being paid or data being leaked, although the deadline for payment has supposedly passed.

The hack of a large and prominent company by a relatively new RaaS group has left the industry with more questions than answers. Anubis has primarily been known as a malware provider for other hacking groups, so it might have seen this attack as a form of self-promotion. However, Coca-Cola’s apparent decision to not pay the ransom is being applauded by many.

To help shed more light on the hack, we were able to catch up with leading industry experts Michael Creen from SonicWall and Cliff Steinhauer from the National Cybersecurity Alliance for input on the hack itself, potential takeaways for other manufacturers, and what this attack reflects about the current state of industrial sector ransomware schemes.

Jeff Reinke, editorial director: There are a couple of different elements associated with this attack. Let's start with Fairlife shutting down production. Does "pulling the plug" feel like a proper response tactic or plan?

Cliff Steinhauer, Director of Information Security & Engagement, National Cybersecurity Alliance: As disruptive as it is, it’s critical to understand the scope of the infection and limit its spread. This is especially true with industrial or mechanical systems, where safety is of utmost importance.

Michael Crean, SVP of Managed Services at SonicWall: I think we could be looking at some potential misconfigurations within the IT environment. This would indicate a human error, not something wrong with the technology. Hopefully, this wasn’t some sort of segmentation issue. In these situations, the challenge is that is you don’t know about many of these potential problems until you experience them.

We don’t know what kind of data was stolen, but it feels like IP or customer data. This could mean the attackers were there for a while. For them to shut operations down, it means they took the threat seriously. I think that’s the hardest thing in the world, and I applaud them for doing that.

JR: The second element is the double extortion ransomware aspect. What does Anubis’ ability to infiltrate and potentially ransom a company the size of Coca-Cola tell us about the evolving threat landscape?

CS: It’s a good reminder that there is no “perfect” or 100 percent secure system. Although Coca-Cola likely has standards, applying them uniformly across varying geographic regions, legacy systems, and scaling to different and often acquired subsidiaries is a task that not many organizations are able to do at a high level. Regional, business unit or other “segmented” divisions have to have strong cyber leadership and management at every level in order to have a chance against today’s cyber threats.

JR: While it's understandable why a company this size would want to minimize an attack in the public's eye, are they doing other manufacturers a disservice by not being more open about the attack?

MC: Sometimes, we don’t think about the data that is being put out there. While it’s helpful to share information, too many details can lead to copycat attacks.

CS: There is always a balance businesses have to take when a cyber incident occurs. Operational security is important to keep a secret because revealing too much about your environment opens the door to attackers to try and poke holes in what they might see as weakness or gaps in a system. On the other hand, it’s absolutely critical that information about the attack is shared, especially within common industry peers. 

This is where ISACs can be a huge benefit (Information Sharing And Analysis Center) where industry peers can openly share threat intelligence without making it public, and keep legally protected information private.

JR: Are there takeaways from this attack that manufacturers can use to elevate their cybersecurity plans or strategies?

MC: Whether you’re a mom and pop or a subsidiary of a big company, everyone is on the radar. That’s the philosophical shift we have to make.

If I’m a betting man, this probably stemmed from an IT exposure. And if that is the case, it goes back to fundamentals like multi-factor authentication, proper credential procedures and other, more condition-based access strategies.

I also think about the Mike Tyson quote: “Everyone has a plan until they get punched in the mouth.” That’s why I think manufacturers would benefit from more tabletop exercises. I spent time in the Army, so I subscribe to the ‘train like you fight’ approach. There’s so much benefit to practicing before an attack, as opposed to waiting until you get punched.

CS: It’s a good opportunity to analyze your defenses, and if budget is needed, you have this as an example to go to your leadership to ask for money to fix gaps in your environment that could be similarly exploited.

JR: Many in cybersecurity feel that more resources and planning should be focused on response, as opposed to prevention or detection. What is your opinion?

MC: Everyone’s response plan should be different. The industry has been prioritizing detection and yet falling short on recovery and response. That needs to change.

CS: I think prevention and detection are equally important as response. Those that say to only focus on response might be throwing up their hands and saying “it’s inevitable” – which it might be, but that doesn’t mean you should make it easy on them. As attackers get better at utilizing AI to find vulnerabilities in your environment, you also have to step up your defenses and proactively run similar stress tests against your systems to identify weaknesses. It’s also critical to continually test your response plans to ensure you are keeping current and build “muscle memory” to minimize any future attack.

More in Cybersecurity