A Levi Strauss cyberattack has led to the theft of corporate data after attackers used social engineering to gain access to three employee devices.

The clothing company said it detected the incident, contained the intrusion and began an investigation. It also brought in external cybersecurity specialists to support its response.

Early findings indicate that the attackers did not view or copy consumer data. Instead, they accessed and removed corporate information stored on the affected employee devices.

Attackers used social engineering

Levi Strauss said an unauthorised third party entered its systems through social engineering. The company did not disclose the exact method used against the three employees.

Social engineering attacks rely on manipulation rather than a technical flaw alone. Criminals may impersonate trusted contacts, send convincing phishing emails or create urgent requests that persuade staff to hand over credentials.

These campaigns remain a major risk for large organisations. One compromised employee account or device can give attackers a foothold into internal systems and sensitive files.

The Levi Strauss cyberattack shows why companies need to prepare staff for deceptive messages and suspicious access requests. Technical controls matter, but employee awareness can help stop an attack before it reaches corporate systems.

Company says consumer data was not affected

The investigation remains ongoing. However, Levi Strauss said preliminary results do not show that consumer information was viewed, copied or exfiltrated.

The company stated that the stolen material consisted of corporate data located on the compromised devices. It has notified affected parties and relevant regulators about the incident.

Levi Strauss also said its containment measures ended the intrusion. Its day-to-day operations continued without disruption during the response.

The company does not expect the incident to have a material effect on its business strategy, operations or financial results.

Levi Strauss faced an earlier account breach

This is not the first security incident connected to the apparel company. In June 2024, Levi Strauss reported a credential-stuffing attack that affected more than 72,000 accounts.

Credential stuffing occurs when attackers test username and password combinations leaked in earlier breaches. Password reuse can make these attacks effective, even when the original compromised service has no direct connection to the targeted company.

The latest incident involved a different route. Attackers reportedly used social engineering to compromise employee devices rather than automated login attempts against customer accounts.

Conclusion

The Levi Strauss cyberattack highlights the continuing danger of social engineering attacks. The company says it contained the breach quickly and found no evidence that consumer data was affected. Still, the incident shows how employee-focused attacks can expose valuable corporate information.


0 responses to “Levi Strauss Cyberattack Exposes Corporate Data”