CyberSecurityNews

Levi Strauss Data Breach – Hackers Gained Access to the Company’s Systems


Levi Strauss & Co., the denim giant, reported a cybersecurity incident where an unauthorized third party accessed the company’s internal systems via a targeted social engineering attack.

According to a regulatory filing submitted to the U.S. Securities and Exchange Commission, the attackers manipulated three employees into surrendering access to their company-issued computers, ultimately allowing the intruders to reach and extract certain corporate files.

Levi Strauss said the unauthorized party used social engineering techniques, a method that relies on psychological manipulation rather than technical exploits, to trick employees into granting access to their devices.

The San Francisco-based apparel maker has not disclosed the exact tactic used, whether phishing emails, deceptive phone calls, or impersonation, but industry reports note that many similar recent attacks have relied on vishing, or voice-based phishing calls impersonating IT staff or help-desk personnel.

Levi Strauss Data Breach

Once inside, the attackers accessed company files stored on the three compromised machines and exfiltrated a portion of that corporate information before the intrusion was detected and shut down.

Upon discovering the breach, Levi Strauss activated its incident response protocols, isolated the affected systems, and brought in third-party cybersecurity experts to investigate the scope of the compromise.

The company stated that its rapid containment measures successfully terminated the unauthorized access, and preliminary findings from the ongoing investigation indicate that no consumer data was affected.

Levi Strauss also confirmed that the incident did not disrupt any business operations, and the company continues to notify affected parties and relevant regulators in line with applicable data protection laws.

In its SEC filing, signed by senior vice president and general counsel David Jedrzejek, Levi Strauss said it does not currently believe the breach will have a material effect on its business strategy, financial condition, or operating results.

The company, which carries a market capitalization of roughly $9.35 billion, emphasized that the investigation remains active and that further details could emerge as the probe progresses.

Levi Strauss now joins a growing roster of major global companies hit by a surge in social engineering-driven cyberattacks and ransomware campaigns over the past several months.

Data reviewed by Reuters shows that threat actors using ransom demands and phone-based social engineering tactics have targeted dozens of prominent U.S. financial institutions and corporations in recent weeks, with more than 200 companies caught in these digital traps over just five weeks.

Just days earlier, a Dutch luxury retail chain also disclosed a cyberattack affecting one of its logistics providers, underscoring how attackers are increasingly exploiting human trust rather than software vulnerabilities to breach enterprise networks [web:8].

The Levi Strauss incident is a reminder that even well-resourced corporations remain vulnerable to low-tech, high-impact tactics like social engineering.

Security experts continue to stress that employee awareness training, multi-factor authentication, and strict verification protocols for IT support requests are critical defenses, especially as AI tools make impersonation and deception campaigns cheaper and more convincing for attackers to execute at scale.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link