Levi Strauss & Co. says attackers stole corporate information after they used social engineering to compromise the company-issued computers of three employees.
The clothing company says it contained the Levi Strauss cyberattack quickly and found no evidence that attackers accessed consumer data. The incident also caused no disruption to normal business operations.
Attackers Targeted Three Levi Strauss Employees
Levi Strauss disclosed the breach in a filing with the US Securities and Exchange Commission. The company says an unknown attacker manipulated three employees through social engineering and gained access to their work devices.
Investigators found that the attackers accessed and removed certain corporate information during the incident.
Levi Strauss says its response team contained the breach and stopped the unauthorised access before the attackers reached consumer data.
The company has not shared details about the stolen corporate information, the social engineering method, or the date it discovered the breach.
Levi Strauss Reports No Business Disruption
The company says the incident has not disrupted operations and should not materially affect its business or financial position.
Levi Strauss employs about 19,000 people and generates annual revenue of roughly $6.3 billion. It operates at least 3,300 stores worldwide and sells products through physical and online third-party retailers. The company remains best known for its 501 jeans line.
Levi Strauss continues to investigate the attack. It says it will contact affected parties when notification requirements apply.
Reports Link Incident to Voice Phishing Campaigns
No threat group has publicly claimed responsibility for the Levi Strauss cyberattack.
Some reports have linked the breach to UNC6671, a threat group connected to a wider wave of voice phishing attacks against hundreds of organisations.
The group reportedly uses helpdesk-style phone scams to trick employees into handing over login credentials or authenticated sessions. Levi Strauss has not confirmed a link between its incident and UNC6671.
Customers Should Watch for Suspicious Activity
Levi Strauss says attackers did not access consumer data. Even so, Levi’s online account holders should watch for suspicious account activity, unexpected password-reset requests and messages that falsely claim to come from the company.
Customers should report suspicious communications directly to Levi Strauss and avoid clicking links or calling phone numbers included in unsolicited messages.


0 responses to “Levi Strauss Cyberattack Exposes Corporate Data After Employee Social Engineering”