Coca-Cola’s Fairlife brand generates roughly $4 billion in annual revenue. In July 2026, production was suspended for 11 days after an Anubis ransomware attack encrypted their Nutanix infrastructure. The pattern appears consistent with most hypervisor attacks: administrative access, reach to the host, workloads taken down, and ends with the datastore encrypted.
That attack path is not unique to Fairlife. It affects hypervisor platforms broadly because most organizations lack dedicated protection at that layer. Endpoint tools and network monitoring do not reach it. Does your organization have a dedicated ESX ransomware protection solution in place, or is its hypervisor layer exposed to the same attack path?
What Happened to Fairlife
On July 16, 2026, Coca-Cola disclosed unauthorized third-party access to Fairlife production systems and suspended production at its four US facilities. Retailers reported milk shortages within days. On July 20, Anubis listed Fairlife on its dark-web leak site with a countdown deadline. Coca-Cola reported the incident to law enforcement, and when the deadline passed on July 27, Anubis published the data it claimed to have taken, reportedly around one terabyte. Fairlife restored most production by that point, though teams were still restoring affected systems.
Why Attackers Target Hypervisors
Nutanix, like VMware ESX and other hypervisor platforms, consolidates compute, storage, networking, and virtualization into a single software-defined layer. That consolidation is what makes it efficient to run, and it’s exactly what makes a hypervisor-layer compromise so damaging: one successful attack at that layer can take down everything running on it, including backup images stored on the same infrastructure.
This isn’t a Nutanix-specific problem. The same attack pattern applies directly to VMware ESX environments. Historically, the hypervisor has received little runtime protection. Most platforms lack built-in MFA for shell access; many also lack behavioral detection for tampering or ransomware activity.
The trend data backs that up. Google Cloud’s Cybersecurity Forecast 2026 flagged virtualization infrastructure as a critical blind spot, warning that a single hypervisor compromise can hand an attacker control of an entire digital estate and disable hundreds of systems within hours. Huntress researchers found the share of ransomware incidents involving hypervisors jumped by 700% in 2025. And MITRE has given ESXi its own dedicated platform in the ATT&CK framework, cataloging techniques like Escape to Host and ESXi Administration Command as established adversary tradecraft.
How the Attack Typically Unfolds in an ESX Environment
The playbook Anubis likely followed breaks into four stages:
- Enable SSH — turn on administrative services to get command-line access to the host.
- Reach the host — SSH straight into ESX. Hypervisors do not have native MFA on shell access.
- Shut down VMs — power off virtual machines so their disk files can be encrypted.
- Encrypt data — delete snapshots, then encrypt every VM on the datastore.
Each stage is a separate control point, not one indivisible breach. This means that each stage can be independently defended, and a defense that only watches for the end state (encrypted files) misses three earlier chances to stop it.
How One Manufacturer Closed This Gap
Food and beverage manufacturing keeps showing up as a target category, and the reasons are structural: heavy reliance on operational technology, perishable production windows that make downtime expensive, and, unfortunately, often hypervisor layers that were never built with runtime security in mind.
A large-scale European beverage manufacturer (anonymized here as CIC, operating as designated critical infrastructure) ran into the same exposure before it became an incident. With roughly 100 hypervisors across 40 locations, CIC’s Head of Infrastructure and Monitoring described mapping out how an attacker could move through their environment: exploit a vulnerability, establish persistence, and quietly escalate credentials until reaching the hypervisor, even in an environment that was kept up to date. As he put it, the exercise made clear “it is not a matter of if — it’s more like when.”
That finding led CIC to research ESX ransomware protection solutions and select ZeroLock®, beginning with a proof of concept before deployment across its VMware environment. The capability the team highlighted most was CLI-MFA for ESX direct access, securing the exact path—SSH into the hypervisor followed by privilege escalation—that its attack analysis had identified as the primary exposure and the route to the kind of disruptive attack Fairlife experienced.
Read the Full Manufacturing Case Study
How to Evaluate an ESX Ransomware Protection Solution
Use these seven criteria as a vendor evaluation checklist when comparing ESX ransomware protection solutions and building a shortlist.
- ESX hardening tool: Look for tamper prevention that maintains hardened hypervisor configurations and prevents administrative services from being silently re-enabled.
- MFA for ESX SSH access: Require CLI-MFA for direct shell sessions so SSH into ESX is not a single-factor path to root.
- Fine-grained lockdown controls: Confirm the solution can block malicious activity such as mass VM shutdowns, not only unauthorized logins.
- Behavioral detection for ESX: Evaluate whether the software recognizes encryption or wipe activity in progress and stops it before completion.
- ESX ransomware recovery: Verify automated rollback and recovery capabilities, including how quickly affected workloads can be restored.
- Deployment model and proof of concept: Compare deployment requirements, operational overhead, and the scope and success criteria of an ESX security POC.
- Vendor references: Ask shortlisted vendors for references from organizations with comparable environments and recovery requirements.
Closing the Hypervisor Protection Gap
Gartner projects preemptive cybersecurity solutions will account for half of all IT security spending by 2030. ZeroLock® applies that preemptive approach to hypervisors with tamper prevention, CLI-MFA, lockdown rules, behavioral ransomware detection, and automated rollback.
For a more structured look, Vali Cyber’s ESX and vCenter risk assessment walks through questions around the MITRE ATT&CK ESXi TTPs and scores where your controls stand. Or reach out directly at [email protected] to see how ZeroLock maps to your environment.