Ransomware Halts Coca-Cola Production & Scattered Spider Jailed (07/16/2026)

July 16, 2026
Ransomware Halts Coca-Cola Production & Scattered Spider Jailed (07/16/2026)
Key Intel / TL;DR
  • Coca-Cola disclosed a ransomware attack on its Fairlife dairy unit that has suspended US production, a brand estimated at $4 billion in sales.
  • Two Scattered Spider members were sentenced to 5 years and 6 months each for the TfL hack that cost £29 million and took 148 systems offline.
  • Ars Technica reports that Russian state actors have adopted ClickFix, a technique that until now belonged to financially motivated criminals.
  • A researcher backdoored an open-weight AI model for under $100 in about an hour, using only ten training examples.
  • More than a million phishing emails are using hidden text to slip past AI security filters.

The interesting thing about today’s lead story is what the attacker probably did not have to touch. Coca-Cola halted Fairlife dairy production across the United States after ransomware hit, and a brand doing an estimated $4 billion in sales stopped making product. Meanwhile two Scattered Spider members went to prison for five and a half years, and ClickFix finished its climb from criminal commodity to state tradecraft.

Top 5 Critical Security Alerts

1. Ransomware Suspends Coca-Cola’s Fairlife Production

Coca-Cola disclosed that a ransomware attack on its Fairlife dairy subsidiary affected “some of its systems, including its production-related systems,” and that US production is “temporarily suspended while the company responds to the incident and restores impacted systems” (BleepingComputer, TechCrunch). Canadian operations are unaffected, no group has claimed it, and the company has not said whether data was taken. Fairlife was estimated at $4 billion in sales by 2024, which sets the scale of what a suspension costs per day.

Operator Note: The disclosure does not say attackers reached the machinery. Production stopped anyway, because stopping was the safe call. That decision is the real blast radius, and it is one you make, not the attacker.

2. Scattered Spider Duo Sentenced to 5.5 Years for the TfL Hack

Thalha Jubair, 20, and Owen Flowers, 18, were each sentenced to five years and six months at Woolwich Crown Court after pleading guilty under Section 3ZA of the Computer Misuse Act (The Record, Infosecurity Magazine). The 2024 attack on Transport for London cost £29 million in recovery, took 148 internal systems offline, and forced all 27,000 staff through in-person password resets.

Operator Note: Twenty-seven thousand people standing in a queue to prove who they are is what identity recovery looks like when the identity system is the casualty. Ask what your version of that queue would be.

3. ClickFix Reaches Russia’s Elite Crews

Ars Technica reports that Russia’s most capable state actors have adopted ClickFix, the paste-this-command trick that has primarily been a tool of financially motivated criminals (Ars Technica). When crews with real budgets pick up the cheap technique, it is not because they ran out of options. It is because it works better than what they were paying for, which is the same economics we covered in why good employees run malicious commands.

4. A $100 Backdoor in an Open-Weight AI Model

Researcher Katie Paxton-Fear, working with Isaac Evans and Cris Thomas, fine-tuned a backdoor into an open-weight model for under $100 in about an hour, needing only ten examples to reliably introduce remote code execution flaws into its output (The Register). The backdoor held across novel prompts and unrelated domains, and larger models were easier to compromise. As the researchers put it, “A compromised or subtly manipulated model doesn’t need to ‘break’ to create business risk, it only needs to influence decisions in ways that are difficult to detect.”

Operator Note: Ten examples and a lunch budget. If a model writes code that reaches production, its provenance is a supply chain question, and right now the weights tell you almost nothing about behavior.

5. A Million Phishing Emails Are Salting Text to Beat AI Filters

More than a million emails are using hidden text, a technique known as text salting, to slip phishing past AI and large language model security filters (Dark Reading). The filter reads one message and the human reads another, which is a cheap way to turn your newest detection layer into a blind spot.

Additional Security Alerts

Threat Intelligence

  • TELEPUZ Spreads Through ClickFix Lures: Elastic Security Labs detailed a modular malware called TELEPUZ that has spread via ClickFix-infected websites since late April 2026, described by researcher Cyril François as “full-featured, lightweight, and modular.” The Hacker News
  • ClickLock Kills Your Apps Until You Type the Password: A new macOS stealer arrives as a command pasted into Terminal, asks for the password behind a fake system dialog, and when the victim cancels, kills their apps on a loop until they give it up. The Hacker News
  • Daxin Resurfaces in Taiwan After Four Years: The China-linked kernel-mode rootkit reappeared inside a Taiwanese manufacturing firm alongside a previously unreported pre-login backdoor dubbed Stupig. The Hacker News

Emerging Security Technologies

  • Agent Data Injection Turns Content Into Commands: A planted product review can make an AI agent click “Buy Now,” and a fake GitHub comment can make a coding assistant run a stranger’s command, without hijacking the agent itself. The Hacker News
  • Claude Chrome Extension Flaw Lets Other Extensions Pull the Trigger: A flaw in Anthropic’s Claude for Chrome extension could let a malicious extension simulate user clicks to trigger AI actions against connected services such as Gmail, Google Docs, and Salesforce. BleepingComputer

Cloud & Network Security

  • n8n Token Exchange Flaw Crosses Issuer Boundaries: A flaw in the workflow automation platform could let an attacker log in as a user from a different identity issuer. The Hacker News

The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.

Distribute Intel
Chris Armour
Director of Information Security
Chris Armour
The Breaker & Builder.

Operating on the philosophy that 'you can't build a secure system if you don't know how to break it,' Chris leads our engineering division. A top 1% National Cyber League competitor, he hardens our digital infrastructure against the very exploits he has mastered.

View Profile →
Press & Media

Media Inquiries

For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.

Initialize Terminal

Initiate
Deployment.

Whether you need a full adversarial facility audit or an executive resilience protocol for your leadership team.

Secure the Facility (Assessments)
Secure the Mind (Coaching/Speaking)