Levi Strauss & Co. has disclosed a cybersecurity incident in which an unknown attacker used social engineering on three of its employees to gain access to and steal corporate data stored on their machines, BleepingComputer reported on August 7. The company filed the disclosure with the U.S. Securities and Exchange Commission (SEC), and Reuters confirmed the breach amid a wider wave of attacks on corporate America.
What Was Taken
Based on preliminary findings from the company's investigation, Levi's believes certain corporate information was accessed and exfiltrated as a result of the incident. The company said its rapid response successfully contained and terminated the unauthorized access, that no consumer data was impacted, and that it has experienced no interruption in business operations — though the investigation remains ongoing, with additional notifications to affected parties expected as required.
Attackers Still Unknown
BleepingComputer could not identify any threat actor claiming responsibility for the attack on Levi's. The company, which employs about 19,000 people and generates annual revenue of $6.3 billion, operates at least 3,300 stores worldwide, best known for its signature 501 jeans — a profile that makes it a high-value target for corporate espionage and ransomware gangs alike.
Why It Matters
The Levi Strauss breach is the latest in a wave of social-engineering attacks targeting corporate workforces, where a handful of compromised employees can hand attackers the keys to sensitive data. That no consumer data was exposed limits the immediate damage, but the incident underscores how quickly attacker-controlled credentials can bypass perimeter defenses — and why multi-factor authentication and anomalous-behavior detection remain the cheapest insurance a company can buy.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.