Friday, September 11, 2026

Levi Strauss Hit by Cyberattack, Hackers Use Social Engineering to Steal Corporate Data

Levi Strauss & Co. has reported a cybersecurity incident in which an unauthorized third party used social engineering techniques to compromise three employee-issued computers and exfiltrate unspecified corporate information.

According to the apparel maker, the intrusion was contained, with no evidence that consumer data was affected or that business operations were disrupted.

Levi Strauss Cyberattack

In a Form 8-K filed with the U.S. Securities and Exchange Commission on August 7, Levi Strauss disclosed that it recently detected unauthorized access to company files after attackers manipulated employees using undisclosed social engineering methods.

The filing does not reveal the identity of the threat actor, the timeline of the intrusion, or the types and volume of corporate data accessed and stolen.

The San Francisco-based company activated its incident-response procedures upon detecting the breach, implemented containment measures, and engaged external cybersecurity experts to support the ongoing investigation.

Levi Strauss stated that its response “successfully contained and terminated” the unauthorized access based on the information available at the time of the filing.

The breach involved three company-issued computers, illustrating how human-targeted attacks can provide adversaries with an entry point without requiring publicly disclosed software exploits or infrastructure vulnerabilities.

The company indicated that the attackers gained access through social engineering, a broad term for techniques that manipulate users into revealing credentials, approving authentication requests, installing remote-access tools, or otherwise enabling access.

Levi Strauss did not specify whether the initial access method involved phishing, voice phishing (vishing), SMS-based lures, help-desk impersonation, credential theft, or multi-factor authentication (MFA) fatigue.

As a result, it is not possible to attribute the incident to a specific tactic, malware family, ransomware operation, or threat group.

Preliminary findings suggest that “certain corporate information” was accessed and exfiltrated. However, the company has not identified the categories of affected data or confirmed whether it included intellectual property, internal communications, financial records, employee information, or partner data.

At the time of reporting, there was no information on ransomware deployment, extortion demands, or public leaks.

Levi Strauss currently believes that no consumer data was impacted and that the incident did not disrupt operations. The company also stated that, based on information available as of its filing date, it does not believe the incident has had or is likely to have a material effect on its business strategy, operations, financial condition, or results.

The organization is notifying affected parties and regulators where required by law. These notifications may evolve as investigators determine the scope of the data exposure and identify any potentially affected individuals or business entities.

This incident underscores that endpoint protections and perimeter controls alone cannot prevent identity-driven intrusions.

Organizations should enhance controls over high-risk employee interactions, including phishing-resistant MFA, help desk identity-verification workflows, privileged access segmentation, endpoint detection and response, and rapid isolation procedures for suspected compromised devices.

For incident-response teams, immediate priorities following a social engineering compromise include revoking active sessions and credentials, reviewing authentication and endpoint telemetry, isolating impacted assets, investigating lateral movement, and assessing data access and exfiltration activity.

The investigation by Levi Strauss is ongoing, and additional technical details may emerge through future notifications or regulatory disclosures.

Stop new phishing & malware before they compromise your business. Integrate live intel from 15K SOCs around the world

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Hot this week

How To Access Dark Web Anonymously and know its Secretive and Mysterious Activities

What is Deep Web The deep web, invisible web, or...

How to Build and Run a Security Operations Center (SOC Guide) – 2023

Today’s Cyber security operations center (CSOC) should have everything...

Russian Hackers Bypass EDR to Deliver a Weaponized TeamViewer Component

TeamViewer's popularity and remote access capabilities make it an...

Web Server Penetration Testing Checklist – 2026

Web server pentesting is performed under three significant categories: identity,...

ATM Penetration Testing – Advanced Testing Methods to Find The Vulnerabilities

ATM Penetration testing, Hackers have found different approaches to...

Researchers Uncover 10,000+ Malware Loaders Behind YouTube and SEO Poisoning Campaign

A long-running pay-per-install (PPI) operation that used YouTube gaming...

VLC Media Player Flaws Let Attackers Corrupt Memory and Leak Sensitive Data

Two security vulnerabilities in VLC media player versions 3.0.0...

CISA Adds Exploited MikroTik RouterOS Flaws to Security Alert

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has...

cPanel Urges Users to Patch ConfigServer Firewall Remote Code Execution Flaw

A recently disclosed vulnerability in ConfigServer Security & Firewall...

Hackers Weaponize AI Safety Guardrails to Hide Malware From LLM-Powered Security Scanners

Threat actors are adapting malware not only for conventional...

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Threat actors are actively exploiting three vulnerabilities in JFrog...

Related Articles

Recent News