Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
What Did They Steal Besides Customer Data?Privacy and Security
5 min readFor Risk Managers

What Did They Steal Besides Customer Data?

When Fairlife's production lines went dark in mid-July, the immediate concern was clear: get the ultra-filtered milk flowing again. The company did that within 11 days. But the questions that followed the ransomware attack reveal a blind spot many risk managers share. What happens when the stolen data isn't credit cards or Social Security numbers, but your operational playbook?

These questions come from conversations I've had with risk teams facing a similar reality: ransomware groups don't just encrypt and ransom anymore. They steal, study, and weaponize what they find. The Anubis group's claim of 671GB from Fairlife included HR records, engineering documentation, and production data. That's not the kind of breach your incident response tabletop typically rehearses.

Here's what risk managers are actually asking when internal data walks out the door.

Do You Know What "Internal Business Data" Means for Incident Classification?

Your incident response structure probably has clear severity levels for customer data exposure. You've got notification timelines mapped to state breach laws and sector-specific regulations. But what's the severity level when someone exfiltrates your supplier contracts, facility layouts, or quality control procedures?

Start by expanding your data classification schema beyond regulated categories. Create an inventory that includes:

  • Operational documentation (production schedules, supplier agreements, facility schematics)
  • Strategic planning materials (M&A targets, market expansion plans, pricing models)
  • Technical specifications (formulas, engineering drawings, system architectures)
  • Internal communications that reveal decision-making processes

Each category needs a defined risk owner and a threshold for what constitutes material impact. When Coca-Cola stated in its Form 8-K that the incident wasn't reasonably likely to have material financial impact, that assessment relied on someone having already mapped which data types could move the needle.

How Do You Assess Risk When Nothing "Regulated" Was Exposed?

This is where traditional risk scoring breaks down. Your cybersecurity risk register probably weights incidents by the presence of personally identifiable information or protected health information. But the Anubis leak demonstrates a different threat model: adversaries who understand that your operational details create leverage.

Build a risk prioritization matrix that includes:

  • Operational continuity risk: Could this data enable a more targeted attack on critical suppliers or single points of failure?
  • Competitive intelligence risk: Does this expose pricing strategies, customer acquisition costs, or product roadmaps?
  • Social engineering risk: Can this data make phishing campaigns against your executives or finance team materially more convincing?
  • Regulatory obligation risk: Even if the data isn't regulated, does its exposure create compliance gaps? (For example, if supplier contracts contain confidentiality clauses you've now breached.)

Fairlife identified unauthorized access on July 16 and resumed most production by July 27. That 11-day window is measurable. The shelf life of stolen engineering documentation and HR records isn't.

What Goes in the Incident Report When There's No Notification Requirement?

You're not filing breach notifications with state attorneys general for stolen production schedules. But that doesn't mean your incident documentation can be thin. Your board, your insurers, and your external auditors will want to understand the exposure.

Document:

  • What was accessed: Be specific about file types, system locations, and data age. "HR records" is too vague. Were these current employee files with home addresses and compensation? Archived records from a facility that closed? The difference matters for downstream risk.
  • What the data enables: This is your threat modeling exercise. If an adversary has your supplier list and production schedules, what becomes possible? Targeted supply chain attacks? Ransomware timed to your peak production periods?
  • What controls failed: Access should be limited, monitored, and separated. Which of those three broke down? Was this a failure of network segmentation, privileged access management, or monitoring/alerting?

Coca-Cola brought in external experts to assist with the response. That's standard. But the real value comes from documenting what those experts found about your control environment, not just what they did to contain the incident.

How Do You Update Business Continuity Plans When the Threat Isn't Just Downtime?

Your business continuity planning probably focuses on getting systems back online and restoring operations. Fairlife did that effectively. But if your competitor now has your production data, or if a threat actor can impersonate your executives using stolen internal communications, you're facing a continuity challenge that doesn't show up in recovery time objectives.

Expand your business continuity scenarios to include:

  • Compromised trust relationships: If vendor impersonation becomes credible because attackers have real contract details, how do you verify payment instructions or change orders?
  • Degraded competitive position: If product formulas or market strategies leak, what's your response? This isn't IT recovery; it's a business strategy question.
  • Sustained social engineering campaigns: If attackers have organizational charts, internal project names, and communication patterns, your phishing defenses just got harder.

The fact that Fairlife's retail availability remained largely unimpacted due to existing inventory is good news for this quarter. It doesn't address what happens when the stolen data gets used six months from now in a targeted campaign against your finance team.

Should You Treat Production Data Like Sensitive Personal Data?

Not identically, but the principle of least privilege applies. Your integrated data privacy capability model probably enforces strict access controls on customer information. Apply the same rigor to operational data that could enable business disruption or competitive harm.

Implement:

  • Role-based access that limits who can view production schedules, supplier lists, or technical specifications
  • Automated control testing that verifies access restrictions are enforced, not just documented
  • Key control indicators that track unusual access patterns to non-customer data repositories

The Anubis group didn't need to steal customer credit cards to create risk. They understood that a dairy company's engineering documentation and production data had value. Your access controls need to reflect that same understanding.

Where Do You Go From Here?

Review your cybersecurity risk register with a specific question: which data types are we underweighting because they don't trigger regulatory notification requirements? Then update your risk-based audit planning to include a review of controls protecting operational and strategic data, not just regulated information.

Your next tabletop exercise should include a scenario where the exfiltrated data is internal business information. Walk through the assessment, documentation, and long-term monitoring steps. The threat actors are already thinking this way. Your incident response structure should too.

Cybersecurity Risk Register

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like