Estados Unidos
fairlife
On July 16, Coca-Cola disclosed a ransomware attack on its dairy subsidiary, fairlife, that disrupted operations and temporarily halted production of fairlife products across the U.S.
In a filing with the U.S. Securities and Exchange Commission (SEC), Coca-Cola said fairlife detected unauthorized access to some of its systems, including production-related systems, in connection with the ransomware attack. The company confirmed that production at fairlife’s U.S. facilities has been temporarily suspended while it responds to the incident and restores impacted systems. However, Coca-Cola said the ransomware attack has not affected product quality or safety.
Meanwhile, the Anubis ransomware gang has listed fairlife on its dark web leak site and is threatening to publish data, adding pressure on the company as it continues its response and recovery efforts.
FuenteCómo puede afectar a su empresa
Ransomware attacks can have consequences far beyond data theft. As this incident demonstrates, they can disrupt production, interrupt business operations and delay the delivery of products and services, resulting in financial losses and operational downtime. To reduce the impact of these attacks, organizations should combine proactive monitoring with a robust business continuity and disaster recovery (BCDR) strategy. Maintaining ransomware-resilient backups and regularly testing recovery processes can help organizations restore critical systems quickly and continue business operations with minimal disruption following a ransomware attack.
Estados Unidos
Craneware
On July 20, U.K.-based health care technology firm Craneware disclosed that it is responding to a cyberattack that may have exposed a significant volume of customer data.
Craneware develops health care billing and revenue cycle management software used by thousands of clinics, hospitals and pharmacies across the U.S. The company’s software helps health care providers bill patients for services and processes large volumes of medical records and patient data on behalf of its customers. In a statement filed with the London Stock Exchange, Craneware said the attackers appear to have been removed from its systems, but its investigation into the incident remains ongoing.
The incident has raised concerns across the U.S. health care sector because of the potential scale of patient data that could be affected. To put that into perspective, when Craneware acquired Florida-based pharmacy software provider Sentry in 2021, the company said it gained access to Sentry’s 147 million patient records collected over two decades.
FuenteCómo puede afectar a su empresa
Cybercriminals are increasingly targeting technology companies that provide software and services to the health care sector. By compromising these providers, attackers can gain access to vast amounts of sensitive medical and health-related data and use the threat of public disclosure to extort organizations. Companies that develop software or provide services to the health care industry should strengthen their cyber defenses with continuous monitoring, strong access controls, regular vulnerability management and a well-tested incident response plan to reduce the risk and impact of these attacks.
América Latina y el Caribe
Ecopetrol
Colombian energy giant Ecopetrol disclosed that thousands of user accounts were affected by a ransomware attack.
The Latin American energy producer said a ransomware attack resulted in the theft of data from 3,300 user accounts. However, the attackers were unable to deploy ransomware or disrupt the company’s day-to-day operations due to its existing security controls. Ecopetrol also said the stolen files were pseudonymized, suggesting the information may have limited value to the attackers.
Meanwhile, reports indicate that an unidentified threat actor contacted Ecopetrol and demanded a ransom payment. However, no details have been disclosed about the amount demanded or whether any of the stolen data has been released publicly.
FuenteCómo puede afectar a su empresa
This incident demonstrates how robust security controls can limit the impact of a ransomware attack. Although attackers stole data, security measures prevented ransomware from encrypting the company’s systems, allowing it to maintain normal operations. Some of the measures organizations can take to strengthen their resilience against ransomware include implementing continuous security monitoring, enforcing multifactor authentication, applying security patches promptly, segmenting critical systems, maintaining ransomware-resilient backups and regularly testing incident response and recovery plans.
Asia y Pacífico
Nichirei Logistics Group
A cyberattack on Japan’s largest cold-chain operator, Nichirei, has had a ripple effect across the country’s food supply chain, disrupting the distribution of frozen and refrigerated products.
On July 13, Nichirei Logistics Group, which transports frozen and refrigerated food for about 5,000 customers across Japan, experienced a system outage. On July 16, the company confirmed that hackers had breached its servers. To contain the attack and protect customer data, Nichirei disconnected key systems, bringing parts of its logistics network to a standstill. The attack disrupted warehouse operations and frozen food shipments.
The disruption quickly spread across the restaurant industry, with more than 1,300 KFC restaurants and other major restaurant chains facing ingredient shortages and struggling to keep up with deliveries.
FuenteCómo puede afectar a su empresa
Cyberattacks on critical supply chain providers can have far-reaching consequences across multiple industries. A single attack on a logistics provider can disrupt operations for thousands of customers, interrupt the delivery of essential goods and create cascading operational and financial impacts throughout the supply chain. Organizations should strengthen supply chain security by assessing third-party cyber risks, continuously monitoring critical vendors, implementing strong security controls across interconnected systems and ensuring business continuity plans account for disruptions affecting key suppliers and service providers.


