Coca-Cola disclosed on July 16, in a filing with the US market regulator, a security incident in which attackers reached parts of the production environment at Fairlife, its dairy subsidiary. The company temporarily suspended production in the United States. On July 20, the group responsible listed the company on its leak site.
What separates this case from most is where the attack landed. A leaked customer database is a data problem. Reaching a production environment is an operations problem: it means the intruder was in the part of the network that controls physical equipment, and the decision to stop a plant is usually precautionary, taken because nobody knows how far they got.
Corporate and industrial networks are supposed to be separated precisely to block that path. When the separation exists only in the diagram, there is usually an undocumented practical bridge: an engineering workstation with access to both sides, a vendor with a remote maintenance connection, a reporting system that needs to read the shop floor.
The cost here isn't measured in exposed records. It's measured in halted production, perishable product, supply contracts and retail deadlines. For food manufacturing, the clock runs faster than in almost any other sector.
The question the case leaves for any industrial operation is easy to ask and uncomfortable to answer: has anyone deliberately tested whether the separation between the administrative network and the production network actually holds?
