Levi Strauss & Co.: Behind the Data Breach Targeting Clothing Giant Levi Strauss

Levi Strauss & Co.: Behind the Data Breach Targeting Clothing Giant Levi Strauss

Levi Strauss Investigates Data Breach Following Social Engineering Attack

Levi Strauss & Co. is probing a data breach after cybercriminals compromised three employee devices using social engineering tactics. The incident, disclosed in an August 7, 2026, regulatory filing, involved attackers gaining access to corporate systems and exfiltrating sensitive information. While the company confirmed that "certain corporate information was accessed and exfiltrated," it stated that no customer data was affected and that the breach is unlikely to have a material impact on operations or finances.

The attack appears linked to a threat group tracked as UNC6671, which employs voice phishing (vishing) to impersonate IT helpdesk staff, tricking employees into entering credentials on spoofed login pages. Using Adversary-in-the-Middle (AiTM) infrastructure, the group intercepts credentials and multi-factor authentication (MFA) tokens, bypassing security controls. This breach is part of a broader surge in cyberattacks, with Reuters reporting that over 200 companies were targeted by ransom-seeking criminals in the past five weeks.

Levi Strauss has engaged third-party cybersecurity experts to assist with containment and investigation, which remains ongoing. The incident underscores the persistent threat of social engineering particularly phishing and vishing as a primary attack vector, even for well-resourced organizations. While the company had previously suffered a June 2024 breach affecting 72,000 accounts, this latest attack highlights the need for real-time data exfiltration prevention, as attackers increasingly prioritize rapid data theft for extortion or resale.

The breach reflects a growing trend of cybercriminals targeting retailers, which hold vast amounts of valuable corporate and customer data. Despite robust defenses, attackers only need a single entry point often through human error to compromise networks.

Source: https://cybermagazine.com/news/levi-strauss-data-breach

Levi Strauss & Co. Europe SCA/ Comm.VA cybersecurity rating report: https://www.rankiteo.com/company/levi-strauss-&-co.-europe-sca-comm.va

"id": "LEV1786467353",
"linkid": "levi-strauss-&-co.-europe-sca-comm.va",
"type": "Breach",
"date": "8/2026",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': 'None (customer data not '
                                              'affected)',
                        'industry': 'Retail (Apparel)',
                        'name': 'Levi Strauss & Co.',
                        'type': 'Corporation'}],
 'attack_vector': 'Social Engineering (Vishing, Phishing)',
 'customer_advisories': 'No customer data was affected',
 'data_breach': {'data_exfiltration': True,
                 'sensitivity_of_data': 'Sensitive',
                 'type_of_data_compromised': 'Corporate information'},
 'date_publicly_disclosed': '2026-08-07',
 'description': 'Levi Strauss & Co. is probing a data breach after '
                'cybercriminals compromised three employee devices using '
                'social engineering tactics. The incident involved attackers '
                'gaining access to corporate systems and exfiltrating '
                'sensitive information. The attack appears linked to a threat '
                'group tracked as UNC6671, which employs voice phishing '
                '(vishing) to impersonate IT helpdesk staff, tricking '
                'employees into entering credentials on spoofed login pages. '
                'Using Adversary-in-the-Middle (AiTM) infrastructure, the '
                'group intercepts credentials and multi-factor authentication '
                '(MFA) tokens, bypassing security controls.',
 'impact': {'data_compromised': 'Corporate information',
            'operational_impact': 'Unlikely to have a material impact on '
                                  'operations',
            'systems_affected': 'Three employee devices, corporate systems'},
 'initial_access_broker': {'entry_point': 'Voice phishing (vishing), spoofed '
                                          'login pages'},
 'investigation_status': 'Ongoing',
 'lessons_learned': 'The incident underscores the persistent threat of social '
                    'engineering, particularly phishing and vishing, as a '
                    'primary attack vector. It highlights the need for '
                    'real-time data exfiltration prevention and the challenges '
                    'of defending against human error.',
 'motivation': 'Data Exfiltration, Extortion, Resale',
 'post_incident_analysis': {'root_causes': 'Social engineering (vishing), AiTM '
                                           'infrastructure, MFA bypass'},
 'ransomware': {'data_exfiltration': True},
 'recommendations': 'Enhance employee training on social engineering tactics, '
                    'implement real-time data exfiltration prevention, and '
                    'strengthen MFA protections against AiTM attacks.',
 'references': [{'source': 'Regulatory filing'}, {'source': 'Reuters'}],
 'regulatory_compliance': {'regulatory_notifications': 'Regulatory filing '
                                                       '(August 7, 2026)'},
 'response': {'communication_strategy': 'Regulatory filing (August 7, 2026)',
              'third_party_assistance': 'Engaged third-party cybersecurity '
                                        'experts'},
 'threat_actor': 'UNC6671',
 'title': 'Levi Strauss Data Breach Investigation Following Social Engineering '
          'Attack',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Adversary-in-the-Middle (AiTM), MFA Bypass'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.