Levi Strauss & Co. Hit by Cyberattack Following Social Engineering Breach
Levi Strauss & Co. confirmed on Friday that unauthorized actors accessed and exfiltrated corporate data after compromising three employee computers through a social engineering attack. The San Francisco-based apparel giant, known for its Levi’s denim brand, disclosed the incident in a U.S. Securities and Exchange Commission (SEC) filing, though it did not specify the type of information stolen.
The company stated that the breach was contained quickly, with no disruption to business operations and no evidence that consumer data was affected. In its filing, Levi Strauss asserted that the incident is unlikely to have a material impact on its financial condition or operations. Details about the attackers, whether ransomware was involved, or if a ransom demand was made remain undisclosed, and no hacking group has claimed responsibility. The investigation is ongoing.
With nearly 3,300 retail stores worldwide, 19,000 employees, and $6.3 billion in net revenue last year, Levi Strauss joins a growing list of retailers targeted by cyber threats. Recent incidents include Dutch luxury retailer De Bijenkorf, which reported delays in orders and potential customer data exposure due to a logistics provider breach, as well as past attacks on brands like Mango, The North Face, Harrods, M&S, and The Co-op. Authorities, including the FBI, continue to warn businesses about the rising risk of social engineering attacks.
Source: https://therecord.media/levis-data-breach-social-engineering
Marks and Spencer cybersecurity rating report: https://www.rankiteo.com/company/marks-and-spencer
Harrods cybersecurity rating report: https://www.rankiteo.com/company/harrods
Levi Strauss & Co. cybersecurity rating report: https://www.rankiteo.com/company/levi-strauss-&-co-
"id": "MARHARLEV1786113277",
"linkid": "marks-and-spencer, harrods, levi-strauss-&-co-",
"type": "Cyber Attack",
"date": "8/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'None (no consumer data '
'affected)',
'industry': 'Apparel/Retail',
'location': 'San Francisco, USA',
'name': 'Levi Strauss & Co.',
'size': '19,000 employees, $6.3 billion net revenue '
'(2023)',
'type': 'Corporation'}],
'attack_vector': 'Social Engineering',
'data_breach': {'data_exfiltration': 'Yes',
'personally_identifiable_information': 'No evidence of '
'consumer data '
'affected',
'type_of_data_compromised': 'Corporate data'},
'description': 'Levi Strauss & Co. confirmed that unauthorized actors '
'accessed and exfiltrated corporate data after compromising '
'three employee computers through a social engineering attack. '
'The breach was contained quickly with no disruption to '
'business operations and no evidence that consumer data was '
'affected.',
'impact': {'data_compromised': 'Corporate data',
'operational_impact': 'No disruption to business operations',
'systems_affected': 'Three employee computers'},
'investigation_status': 'Ongoing',
'references': [{'source': 'U.S. Securities and Exchange Commission (SEC) '
'filing'}],
'regulatory_compliance': {'regulatory_notifications': 'SEC filing'},
'response': {'communication_strategy': 'SEC filing disclosure',
'containment_measures': 'Breach contained quickly'},
'title': 'Levi Strauss & Co. Cyberattack Following Social Engineering Breach',
'type': 'Data Breach'}