Daylila

Cybersecurity · Monday, 20 July 2026

01 · Briefing · what happened

Coca-Cola stopped bottling milk — and three companies this week shut their own systems down

Cybersecurity 7 min 69 sources

Fairlife paused US production after a ransomware attack, a Japanese frozen food giant disconnected its warehouses, and Japan's biggest taxi firm took its dispatch system offline. In each case the visible damage came from the company pulling its own plug, because nobody yet knew how far the intruder had got.

Key takeaways

  • Coca-Cola paused US production of Fairlife milk after a ransomware attack, and two Japanese firms disconnected their own systems the same week — in each case because nobody yet knew how far the attacker had reached.
  • Breach notices this week lean on phrases like "we cannot rule out" and "as a precaution," which are honest admissions of how little a company can see straight after an intrusion.
  • India's markets regulator warned of a "boss scam" where fraudsters impersonate senior executives to order payments — a message from a real account is not proof of a real sender, so confirm on another channel.

Three companies on two continents did the same thing this week. Each found an intruder in its systems. Each responded by switching large parts of its own business off. And each said, in almost the same words, that it did not yet know how far the attacker had reached.

That last part is the story.

Milk stops in Chicago

Coca-Cola suspended US production at Fairlife, its lactose-free milk and protein-shake brand, after what the company called a ransomware event [25]. Attackers got unauthorised access to a portion of Fairlife’s systems, including those tied to production, and Coca-Cola took some operations offline in response [25].

Ransomware is malicious software that scrambles a company’s files and holds them hostage, usually with a demand for payment to restore access. It is often paired with theft — copy the data first, then encrypt it, so there are two ways to squeeze the victim.

Coca-Cola said product quality and safety were not affected, but that production at Fairlife in the United States is temporarily suspended [25]. Canadian operations kept running [25]. The company told the Associated Press the full scope and impacts of the attack were otherwise still unknown [25]. It had informed law enforcement and brought in outside security experts [25]. SecurityWeek put the same point more bluntly: the company has yet to determine the full scope, nature and impact of the incident [6].

Fairlife is not a small line. The Chicago-based brand claims more than $3 billion in annual retail sales [25].

The same move, twice more, in Japan

On 13 July, Nichirei — one of Japan’s largest frozen food producers, which also runs cold-storage warehouses and operates through 80 subsidiaries — disconnected its systems after a cyberattack [34]. That took down refrigerated warehouse operations and shipping, and the disruption reached restaurant chains, retailers and delivery services, according to local reporting [34]. Nichirei said its investigation established that attackers targeted its servers, and that some affected systems held personal information [34]. It filed an initial report to Japan’s Personal Information Protection Commission as a matter involving the possibility of leakage — not a confirmed one [34].

Days earlier, Nihon Kotsu, Japan’s largest taxi and chauffeur operator, was hit over a weekend [47]. The firm said it detected unauthorised external access and immediately disconnected systems to prevent further damage [47]. Its taxi dispatch system went offline, along with web booking, reservation management and phone dispatch [47]. Nihon Kotsu runs 8,558 taxis and employs more than 18,000 people [47].

One consequence lands harder than the rest. Nihon Kotsu suspended its “labor taxi” service — the booking service used by pregnant women close to giving birth — across Tokyo, Musashino, Mitaka, Tachikawa, Yokohama and Saitama [47]. The company pointed customers to a rival app or to taxi ranks [47]. It said it was still looking into whether data had leaked, and that no leak had been confirmed [47]. An extortion group calling itself AiLock later claimed the attack and threatened to publish stolen data [47].

”We cannot rule out” is doing a lot of work

The same uncertainty runs through this week’s breach notices. It is worth reading them closely. The careful wording is not evasion — it is an honest report of what a company can and cannot see.

Lidl told customers in Germany, Belgium and the Netherlands that attackers briefly reached a file of customer data held at a service provider [40]. Part of it was stolen [40]. Names, phone numbers, email addresses, dates of birth and customer numbers went [40]. Lidl says it can rule out passwords, payment details and addresses, and that the online shop’s own systems were untouched [40]. But it also told customers it has no concrete evidence of misuse, and is warning them as a precaution [24]. That is the polite form of we do not know what happens to this data next.

The gap between an intrusion and a full count can be enormous. Centers Laboratory, a New Jersey diagnostics provider, has now told the US government that a breach it discovered in August 2025 affects 542,377 people [1]. Attackers had limited access for five days in August, taking names, dates of birth, Social Security numbers, driver’s licence and passport numbers, and health insurance and medical information [1]. The extortion group WorldLeaks listed the company in October 2025 and leaked more than 1.6 million files [1]. The individual count landed with the Department of Health and Human Services last week — roughly a year after the intrusion [1].

In Australia, Partnered Health said a malicious actor reached its data on 23 June, affecting 21 clinics across Sydney, Melbourne and Canberra [14]. Treatment details, consultation notes, referral letters, pathology results, Medicare numbers and insurance details are believed stolen [14]. The company won a court injunction ordering the data not be used or published [14]. It told the Guardian it was not in patients’ interests to say publicly how many people were affected [14]. An injunction from a New South Wales court is unlikely to constrain a buyer on a hidden marketplace [14].

Clover Health, a US health insurer, offers a tidier example of what visibility buys you. It detected unusual login activity on 4 July [22]. It later established that an attacker had reached exactly three employee accounts, belonging to non-managerial health plan staff [22]. The way in was social engineering — tricking a person rather than breaking software [22]. Abbott, meanwhile, is investigating two separate incidents and says they are unrelated, after the ShinyHunters extortion group listed it and set a deadline [7][2].

If you shop at Lidl online, or have used a US diagnostics lab, treat any message referencing the breach with suspicion. Stolen name-and-birthday sets are raw material for convincing scam calls and emails. A real company will not phone you to ask for a password or a code.

When the picture finally clears

It does clear, eventually — just slowly.

Two British men were sentenced on Thursday to five and a half years each for the 2024 attack on Transport for London [36]. The attack cost £29 million and six months of work to fix [36]. Thalha Jubair, 20, and Owen Flowers, 18, worked up to 16 hours a day, one from his parents’ flat in east London, the other from his grandmother’s home [36]. Jubair livestreamed the intrusion; Flowers watched, and the video on his laptop became key evidence [36]. Prosecutors said the pair could have shut TfL down completely, and that the attack was stopped only when TfL pulled the plug on its own systems [36][44].

Two years to reach that account. On the night, TfL did what Coca-Cola and Nichirei did this month.

Separately, the US Treasury sanctioned First VPN Service and its Ukrainian administrator, Dmytro Rashevskyi [32][26]. The service gave ransomware groups tools to hide their identities and evade detection [32]. Treasury says those attacks caused billions in losses to US critical infrastructure [32]. A Belarusian national, Yegeniy Vladimirovich Silayev, was designated separately for selling software that disguises malware as harmless files [32].

The under-covered one: someone will email you pretending to be your boss

India’s markets regulator issued a warning on Friday about what it called the “boss scam” [29]. Fraudsters impersonate a chief executive or another senior figure and instruct a finance employee to move money to an account they control [29]. The Securities and Exchange Board of India said it acted after the Indian Cyber Crime Coordination Centre reported rising cases [29].

The approach comes by email, WhatsApp, Microsoft Teams or social media [29]. A second version sends a malicious file; open it and the attacker can hijack a WhatsApp Web session, then message finance staff from the finance officer’s real account [29].

That second variant is the nasty one, and it is not only a corporate problem. A message from a genuine account is not proof of a genuine sender. If a request to move money or share a code arrives — even from a familiar name, on a familiar app — confirm it on a different channel before acting. Call the person. Urgency is the tell; every version of this scam is built to stop you checking.

02 · Lesson · why it matters

When you can't see how far it went, you have to assume everywhere

The damage people feel from an attack is usually the shutdown — and the size of the shutdown is set by how little the defender can see.

The decision at two in the morning

An alert fires on one server. Something is in the system that should not be there. You have maybe an hour before it matters, and one question in front of you: how much do you switch off?

Coca-Cola answered by stopping US milk production. Nichirei answered by disconnecting refrigerated warehouses and shipping. Nihon Kotsu answered by taking its taxi dispatch offline, including the booking service pregnant women use to reach a hospital.

None of those systems were broken. The milk plant could bottle. The taxis could drive. Someone chose to stop them.

That choice is what the public actually experienced this week. Not the intrusion — the response to it.

You can only measure what you can see

Here is the thing that makes the decision hard. On the night, nobody knows the answer to the only question that matters: how far did they get?

An intruder who reaches one machine is a small problem. The same intruder, having quietly moved to twenty machines over three weeks, is a company-ending one. From the outside, on hour one, those two situations look identical. One alert. One strange login.

So the defender is not choosing between a small response and a large one. They are choosing under a fog, and the fog has a shape. The less of your own system you can reconstruct, the wider the range of things that might be true.

Call it the blast radius you cannot measure. You still have to act on it. And the only way to act safely on a number you don’t know is to assume the number is large.

The errors are not symmetrical

Cut too wide and you lose days of production. That is expensive, visible, and survivable. You know exactly what it cost, because you can count the milk that didn’t ship.

Cut too narrow and the intruder keeps moving through everything you left connected. You will have to cut again in three days — wider, from a worse position, having taught them what you can detect. That cost is unbounded and you cannot see it coming.

When one error is bounded and the other isn’t, the rational move is to overshoot. Every one of these companies overshot on purpose. That is not panic. It is the correct play with the information available.

Which means the shutdown is not really a measure of how bad the attack was. It is a measure of how much the defender didn’t know.

What some companies actually bought

Set this week’s cases side by side and a difference shows up that has nothing to do with who had stronger walls.

Clover Health could say the attacker reached exactly three employee accounts, and that they belonged to non-managerial staff. It could name the way in: social engineering — a person tricked, not software broken. Abbott could say a limited number of internal systems in one named business unit. Coca-Cola, a week in, could say the full scope was still unknown.

The first two made narrow, cheap responses. The third stopped a production line.

The difference is the ability to reconstruct the night afterwards. Records of who logged in where, kept long enough and joined up well enough to answer a question you didn’t know you’d be asked. That capacity is boring and it is the whole game. It is also the thing that is easiest to defer, because it produces nothing on a good day. It shows up in the accounts as overhead. The shutdown it would have prevented shows up as a bad week that never arrives, and nobody gets credit for a week that never arrives.

The part that was decided before anyone was attacked

Lidl’s customer data was not taken from Lidl. It sat in a file at a service provider, and that is where it was stolen.

This is where the arrangement underneath becomes visible. Handing customer data to a specialist supplier is ordinary, and it is not a trick played on anyone. It is cheaper, it is often more competently run than an in-house version, and some of that saving does reach the shopper. Nobody chose it in order to create uncertainty.

But it does create uncertainty, and it moves the fog somewhere specific. The company that must answer to its customers is not the company that can see what happened. Lidl can tell you the online shop wasn’t touched. It cannot tell you, with the same confidence, what a third party’s logs would show, because those are not its logs.

So the honest notice reads: we have no concrete evidence of misuse; we are warning you as a precaution. That sentence is not corporate hedging. It is an accurate description of a company reporting on a room it cannot enter.

Who is standing in the fog

The woman in Musashino who booked a taxi to get to hospital and found the service suspended was never a target of anything. She was downstream of a decision made in a room she never saw, about a risk nobody could size.

So was the shopper looking at a gap where the milk usually is. So is anyone holding a letter that says their date of birth and passport number may have been taken. It may be for sale. It may already be with someone who will call them next month sounding official.

That reader has the same problem the company had at two in the morning, only further out and with less to work with. They cannot check. They cannot count. They are being asked to act sensibly on a number nobody has.

There is a kind of clarity in noticing that the uncertainty runs all the way up. The people at the centre of this spent a week not knowing either. They had the response teams, the outside experts, the legal obligation to file a report. The most truthful sentence any of them published was that they could not yet say. From where the rest of us sit, further down the chain and holding less, the honest position is at least as loose.

03 · Lab · your turn

The Cut You Can't Size

Rehearse a containment call when you cannot see how far an intruder reached, and feel why thin records force the expensive shutdown.

04 · Hope · carry this

Every one of those shutdowns was someone choosing a lost week over a risk they could not measure. Paying a known cost to spare an unknown harm is a quiet habit, and it is holding up more of this than we notice.

Across the beats