Illustrative image generated with AI
Social Engineering Attack Against Levi Strauss: Computers of Three Employees Compromised
Levi Strauss reports social engineering cyberattack compromising three employees' computers. Potential data exfiltration, but no customer data theft confirmed. Investigation ongoing.
Text generated by artificial intelligence, published without human review. AI transparency
Access to Corporate Systems and Potential Data Exfiltration
Levi Strauss & Co. disclosed a cyberattack involving social engineering techniques in a Form 8-K filing with the U.S. Securities and Exchange Commission.
The attackers compromised the corporate computers assigned to three employees. Preliminary findings indicate that they may have accessed and exfiltrated internal information.
The attacker’s identity has not been disclosed. The company did not specify whether any ransom demands were made or which specific technique was used.
No Preliminary Evidence of Customer Data Theft
Based on the investigation conducted so far, Levi Strauss has found no evidence that customer data was stolen. The potential impact therefore appears limited to corporate information, although no details have been released about its type or volume.
The company believes the incident did not have, and is not reasonably likely to have, a material impact. No disruption to business operations has been reported.
Unconfirmed reports suggest possible involvement by UNC6671, a group associated with voice phishing campaigns. Levi Strauss has not confirmed this attribution.
Containment Completed, Investigation Ongoing
The company implemented immediate response and containment measures. The attackers have reportedly been removed from the compromised computers.
The investigation remains ongoing. No indicators of compromise, forensic details, potentially exfiltrated data, or additional technical countermeasures have been disclosed.
No specific software products, versions, vulnerabilities, or CVE identifiers have been linked to the incident. Consequently, there is no dedicated patch to install.
What Organizations Should Check
Because the initial access is believed to have involved social engineering, organizations should verify the authenticity of requests received by phone or through other channels, especially those involving credentials, remote access, or data transfers.
In the absence of publicly available indicators, it is not possible to associate the incident with specific files, addresses, or domains. Organizations concerned should therefore focus on the account logs of the three affected employees, anomalous access activity, and transfers of corporate information.
Sources
This article is an original reworking based on the sources below.
