Criminal group behind Anubis ransomware claims breach of dairy company Fairlife, leveraging SharePoint vulnerability that survives system updates.
Fairlife, a major dairy and nutritional beverage producer, has become the latest victim of Anubis ransomware operators. The attackers allege they've stolen sensitive company information and are threatening to publish the data unless a ransom is paid. What makes this incident particularly concerning is the technical method behind the intrusion: criminals are exploiting a serious flaw in Microsoft SharePoint that allows them to maintain a permanent foothold on compromised systems.
The attackers are weaponizing CVE-2026-50522, a critical SharePoint vulnerability. Think of it like a burglar breaking into a house, then hiding a hidden key behind a brick so they can return even after the homeowner changes all the locks. When a company patches (fixes) their SharePoint servers, this particular vulnerability allows hackers to extract "machine keys" โ special digital credentials that grant ongoing access to systems. Even after the initial entry point is sealed, these stolen keys continue working, making it extremely difficult for defenders to completely remove the intruders.
This attack pattern represents a fundamental shift in how ransomware criminals operate. Rather than forcing their way out after stealing data, these groups are establishing permanent backdoors that can be used for months or years. It's the difference between a one-time robbery and a criminal installing a secret tunnel into your home.
For Fairlife specifically, the breach exposes how even well-known companies with reasonable security budgets remain vulnerable to determined attackers. The dairy company's internal documents and potentially customer information now sit in criminal hands, creating both immediate and long-term business risks.
This attack demonstrates that patching systems is no longer sufficient as a standalone defense strategy.
If you work in IT or cybersecurity, this incident underscores that vulnerabilities in widely-used enterprise software like SharePoint demand urgent attention. Your organization likely uses similar systems.
If you're a consumer, understand that data breaches at major food and beverage companies can expose personal information collected through loyalty programs, online ordering, or nutritional tracking services. Fairlife's breach could compromise millions of customer records.
For business leaders, this illustrates why security requires multiple layers. A single patch isn't enough when attackers can bypass it through stolen credentials.
The Fairlife incident belongs to a troubling trend where ransomware groups focus on establishing permanent access rather than quick smash-and-grab operations, making detection and removal substantially harder for victims.
Organizations must recognize that security is now a continuous process, not a series of one-time fixes.
Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.
Explore IT Chapters โ