Cybersecurity · Monday, 20 July 2026
01 · Briefing · what happened
Coca-Cola stopped bottling milk — and three companies this week shut their own systems down
Fairlife paused US production after a ransomware attack, a Japanese frozen food giant disconnected its warehouses, and Japan's biggest taxi firm took its dispatch system offline. In each case the visible damage came from the company pulling its own plug, because nobody yet knew how far the intruder had got.
Key takeaways
- Coca-Cola paused US production of Fairlife milk after a ransomware attack, and two Japanese firms disconnected their own systems the same week — in each case because nobody yet knew how far the attacker had reached.
- Breach notices this week lean on phrases like "we cannot rule out" and "as a precaution," which are honest admissions of how little a company can see straight after an intrusion.
- India's markets regulator warned of a "boss scam" where fraudsters impersonate senior executives to order payments — a message from a real account is not proof of a real sender, so confirm on another channel.
Three companies on two continents did the same thing this week. Each found an intruder in its systems. Each responded by switching large parts of its own business off. And each said, in almost the same words, that it did not yet know how far the attacker had reached.
That last part is the story.
Milk stops in Chicago
Coca-Cola suspended US production at Fairlife, its lactose-free milk and protein-shake brand, after what the company called a ransomware event
Ransomware is malicious software that scrambles a company’s files and holds them hostage, usually with a demand for payment to restore access. It is often paired with theft — copy the data first, then encrypt it, so there are two ways to squeeze the victim.
Coca-Cola said product quality and safety were not affected, but that production at Fairlife in the United States is temporarily suspended
Fairlife is not a small line. The Chicago-based brand claims more than $3 billion in annual retail sales
The same move, twice more, in Japan
On 13 July, Nichirei — one of Japan’s largest frozen food producers, which also runs cold-storage warehouses and operates through 80 subsidiaries — disconnected its systems after a cyberattack
Days earlier, Nihon Kotsu, Japan’s largest taxi and chauffeur operator, was hit over a weekend
One consequence lands harder than the rest. Nihon Kotsu suspended its “labor taxi” service — the booking service used by pregnant women close to giving birth — across Tokyo, Musashino, Mitaka, Tachikawa, Yokohama and Saitama
”We cannot rule out” is doing a lot of work
The same uncertainty runs through this week’s breach notices. It is worth reading them closely. The careful wording is not evasion — it is an honest report of what a company can and cannot see.
Lidl told customers in Germany, Belgium and the Netherlands that attackers briefly reached a file of customer data held at a service provider
The gap between an intrusion and a full count can be enormous. Centers Laboratory, a New Jersey diagnostics provider, has now told the US government that a breach it discovered in August 2025 affects 542,377 people
In Australia, Partnered Health said a malicious actor reached its data on 23 June, affecting 21 clinics across Sydney, Melbourne and Canberra
Clover Health, a US health insurer, offers a tidier example of what visibility buys you. It detected unusual login activity on 4 July
If you shop at Lidl online, or have used a US diagnostics lab, treat any message referencing the breach with suspicion. Stolen name-and-birthday sets are raw material for convincing scam calls and emails. A real company will not phone you to ask for a password or a code.
When the picture finally clears
It does clear, eventually — just slowly.
Two British men were sentenced on Thursday to five and a half years each for the 2024 attack on Transport for London
Two years to reach that account. On the night, TfL did what Coca-Cola and Nichirei did this month.
Separately, the US Treasury sanctioned First VPN Service and its Ukrainian administrator, Dmytro Rashevskyi
The under-covered one: someone will email you pretending to be your boss
India’s markets regulator issued a warning on Friday about what it called the “boss scam”
The approach comes by email, WhatsApp, Microsoft Teams or social media
That second variant is the nasty one, and it is not only a corporate problem. A message from a genuine account is not proof of a genuine sender. If a request to move money or share a code arrives — even from a familiar name, on a familiar app — confirm it on a different channel before acting. Call the person. Urgency is the tell; every version of this scam is built to stop you checking.
02 · Lesson · why it matters
When you can't see how far it went, you have to assume everywhere
The damage people feel from an attack is usually the shutdown — and the size of the shutdown is set by how little the defender can see.
The decision at two in the morning
An alert fires on one server. Something is in the system that should not be there. You have maybe an hour before it matters, and one question in front of you: how much do you switch off?
Coca-Cola answered by stopping US milk production. Nichirei answered by disconnecting refrigerated warehouses and shipping. Nihon Kotsu answered by taking its taxi dispatch offline, including the booking service pregnant women use to reach a hospital.
None of those systems were broken. The milk plant could bottle. The taxis could drive. Someone chose to stop them.
That choice is what the public actually experienced this week. Not the intrusion — the response to it.
You can only measure what you can see
Here is the thing that makes the decision hard. On the night, nobody knows the answer to the only question that matters: how far did they get?
An intruder who reaches one machine is a small problem. The same intruder, having quietly moved to twenty machines over three weeks, is a company-ending one. From the outside, on hour one, those two situations look identical. One alert. One strange login.
So the defender is not choosing between a small response and a large one. They are choosing under a fog, and the fog has a shape. The less of your own system you can reconstruct, the wider the range of things that might be true.
Call it the blast radius you cannot measure. You still have to act on it. And the only way to act safely on a number you don’t know is to assume the number is large.
The errors are not symmetrical
Cut too wide and you lose days of production. That is expensive, visible, and survivable. You know exactly what it cost, because you can count the milk that didn’t ship.
Cut too narrow and the intruder keeps moving through everything you left connected. You will have to cut again in three days — wider, from a worse position, having taught them what you can detect. That cost is unbounded and you cannot see it coming.
When one error is bounded and the other isn’t, the rational move is to overshoot. Every one of these companies overshot on purpose. That is not panic. It is the correct play with the information available.
Which means the shutdown is not really a measure of how bad the attack was. It is a measure of how much the defender didn’t know.
What some companies actually bought
Set this week’s cases side by side and a difference shows up that has nothing to do with who had stronger walls.
Clover Health could say the attacker reached exactly three employee accounts, and that they belonged to non-managerial staff. It could name the way in: social engineering — a person tricked, not software broken. Abbott could say a limited number of internal systems in one named business unit. Coca-Cola, a week in, could say the full scope was still unknown.
The first two made narrow, cheap responses. The third stopped a production line.
The difference is the ability to reconstruct the night afterwards. Records of who logged in where, kept long enough and joined up well enough to answer a question you didn’t know you’d be asked. That capacity is boring and it is the whole game. It is also the thing that is easiest to defer, because it produces nothing on a good day. It shows up in the accounts as overhead. The shutdown it would have prevented shows up as a bad week that never arrives, and nobody gets credit for a week that never arrives.
The part that was decided before anyone was attacked
Lidl’s customer data was not taken from Lidl. It sat in a file at a service provider, and that is where it was stolen.
This is where the arrangement underneath becomes visible. Handing customer data to a specialist supplier is ordinary, and it is not a trick played on anyone. It is cheaper, it is often more competently run than an in-house version, and some of that saving does reach the shopper. Nobody chose it in order to create uncertainty.
But it does create uncertainty, and it moves the fog somewhere specific. The company that must answer to its customers is not the company that can see what happened. Lidl can tell you the online shop wasn’t touched. It cannot tell you, with the same confidence, what a third party’s logs would show, because those are not its logs.
So the honest notice reads: we have no concrete evidence of misuse; we are warning you as a precaution. That sentence is not corporate hedging. It is an accurate description of a company reporting on a room it cannot enter.
Who is standing in the fog
The woman in Musashino who booked a taxi to get to hospital and found the service suspended was never a target of anything. She was downstream of a decision made in a room she never saw, about a risk nobody could size.
So was the shopper looking at a gap where the milk usually is. So is anyone holding a letter that says their date of birth and passport number may have been taken. It may be for sale. It may already be with someone who will call them next month sounding official.
That reader has the same problem the company had at two in the morning, only further out and with less to work with. They cannot check. They cannot count. They are being asked to act sensibly on a number nobody has.
There is a kind of clarity in noticing that the uncertainty runs all the way up. The people at the centre of this spent a week not knowing either. They had the response teams, the outside experts, the legal obligation to file a report. The most truthful sentence any of them published was that they could not yet say. From where the rest of us sit, further down the chain and holding less, the honest position is at least as loose.
03 · Lab · your turn
The Cut You Can't Size
Rehearse a containment call when you cannot see how far an intruder reached, and feel why thin records force the expensive shutdown.
04 · Hope · carry this
Every one of those shutdowns was someone choosing a lost week over a risk they could not measure. Paying a known cost to spare an unknown harm is a quiet habit, and it is holding up more of this than we notice.
More from Cybersecurity