Levi's Breach Exposes Social Engineering Threat
Levi Strauss investigates a breach after attackers used social engineering to access employee PCs and exfiltrate corporate data.
Levi Strauss is investigating a data breach after attackers used social engineering to access three employees' work computers, according to a regulatory filing. The intruders accessed and exfiltrated what the jeans maker described only as "certain corporate information." The company said it spotted the intrusion, kicked off its incident response procedures, brought in outside cybersecurity experts, and managed to cut off the unauthorized access. Its investigation remains ongoing.
Social Engineering Attack Details
In the filing, Levi's said the attackers used social engineering to compromise the three employee PCs. The company did not specify the exact method used in this incident, but reports indicate that the broader campaign involved phone calls to employees on their personal mobiles, posing as colleagues or IT support staff, and directing them to spoofed login pages designed to harvest credentials and multi-factor authentication codes.
Levi's reported that its preliminary investigation indicates that no consumer data was affected. The company also said the attack caused no disruption to its operations and, based on what it knows so far, isn't expected to have a material impact on its business. Affected parties and regulators will be notified where required.
Broader Campaign Context
Reuters reported that Levi's was among more than 200 organizations targeted over the past five weeks by ransom-seeking hackers using these old-school social engineering techniques. Google researchers have been tracking several crews involved in the wider campaign, which they believe may sit under an umbrella group dubbed UNC6671.
The attackers have been phoning employees on their personal mobiles while posing as colleagues or IT support staff, then directing them to spoofed login pages designed to harvest credentials and multi-factor authentication codes. The targets have included financial and legal firms handling information that can make for particularly effective extortion fodder, although Google says the attackers have previously gone after organizations across manufacturing, healthcare, insurance, technology, and hospitality too.
Response and Containment
Levi's said it spotted the intrusion and kicked off its incident response procedures, bringing in outside cybersecurity experts to assist. The company managed to cut off the unauthorized access, and its investigation remains ongoing. For now, Levi's appears to have contained the breach before its attackers could get any deeper into its pockets.
There's no confirmation that UNC6671 was behind the successful Levi's intrusion, nor has the denim dealer said exactly what was stolen or whether anyone tried to extort it.
Key Numbers
- Three employees' work computers were accessed.
- More than 200 organizations targeted over the past five weeks.
- Levi's reported no consumer data was affected.
Why It Matters
This incident underscores the persistent threat of social engineering, which preys on human trust rather than technical vulnerabilities. Even with robust security measures like multi-factor authentication, attackers can bypass them by tricking employees into handing over credentials. For businesses, this highlights the need for ongoing employee training and vigilance against phone-based phishing attempts, as well as the importance of rapid detection and response to limit the impact of a breach.
Sources
- The Register Original source
Continue Reading
Hostile SIMs exploit spec-compliant commands
Malicious SIM cards can force phones to leak files, drop to 2G, or crash—by abusing standard SIM commands.
Gray to White: A Hacker's Redemption Arc
Marcus Hutchins, who halted WannaCry, recounts his path from malware author to security researcher.
Cyber Prep Gap Leaves UK Factories Vulnerable
New Make UK report finds half of UK manufacturers lack a formal cyber incident response plan despite rising incidents.