Breaking
SecurityConfirmed

Levi's Breach Exposes Social Engineering Threat

Levi Strauss investigates a breach after attackers used social engineering to access employee PCs and exfiltrate corporate data.

··6 hours ago·2 min read
icon
Photo by GuerrillaBuzz on Unsplash

Levi Strauss is investigating a data breach after attackers used social engineering to access three employees' work computers, according to a regulatory filing. The intruders accessed and exfiltrated what the jeans maker described only as "certain corporate information." The company said it spotted the intrusion, kicked off its incident response procedures, brought in outside cybersecurity experts, and managed to cut off the unauthorized access. Its investigation remains ongoing.

Social Engineering Attack Details

In the filing, Levi's said the attackers used social engineering to compromise the three employee PCs. The company did not specify the exact method used in this incident, but reports indicate that the broader campaign involved phone calls to employees on their personal mobiles, posing as colleagues or IT support staff, and directing them to spoofed login pages designed to harvest credentials and multi-factor authentication codes.

Levi's reported that its preliminary investigation indicates that no consumer data was affected. The company also said the attack caused no disruption to its operations and, based on what it knows so far, isn't expected to have a material impact on its business. Affected parties and regulators will be notified where required.

Broader Campaign Context

Reuters reported that Levi's was among more than 200 organizations targeted over the past five weeks by ransom-seeking hackers using these old-school social engineering techniques. Google researchers have been tracking several crews involved in the wider campaign, which they believe may sit under an umbrella group dubbed UNC6671.

The attackers have been phoning employees on their personal mobiles while posing as colleagues or IT support staff, then directing them to spoofed login pages designed to harvest credentials and multi-factor authentication codes. The targets have included financial and legal firms handling information that can make for particularly effective extortion fodder, although Google says the attackers have previously gone after organizations across manufacturing, healthcare, insurance, technology, and hospitality too.

Response and Containment

Levi's said it spotted the intrusion and kicked off its incident response procedures, bringing in outside cybersecurity experts to assist. The company managed to cut off the unauthorized access, and its investigation remains ongoing. For now, Levi's appears to have contained the breach before its attackers could get any deeper into its pockets.

There's no confirmation that UNC6671 was behind the successful Levi's intrusion, nor has the denim dealer said exactly what was stolen or whether anyone tried to extort it.

Key Numbers

  • Three employees' work computers were accessed.
  • More than 200 organizations targeted over the past five weeks.
  • Levi's reported no consumer data was affected.

Why It Matters

This incident underscores the persistent threat of social engineering, which preys on human trust rather than technical vulnerabilities. Even with robust security measures like multi-factor authentication, attackers can bypass them by tricking employees into handing over credentials. For businesses, this highlights the need for ongoing employee training and vigilance against phone-based phishing attempts, as well as the importance of rapid detection and response to limit the impact of a breach.

#levi strauss#social engineering#data breach#cybersecurity

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories