Levi Strauss & Co. has confirmed that corporate data was stolen in a recent cyberattack that leveraged social engineering against three of its employees. The apparel company disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), stating that its rapid response prevented any compromise of consumer data.
According to Levi's, the attackers used social engineering tactics to gain unauthorized access to company-issued computers belonging to the three employees. This access led to the exfiltration of certain corporate information. The company, known for its 501-line jeans and operating over 3,300 stores globally, has an annual revenue of $6.3 billion and approximately 19,000 employees.
The investigation into the breach is ongoing. However, Levi's has stated that it does not believe the incident will materially impact its business operations or financial standing, and no operational disruptions have been reported. The company also emphasized that its swift containment efforts successfully terminated the unauthorized access.
While Levi's has not publicly identified the threat actors responsible, some reports have speculated a connection to UNC6671. This group has been linked by Google's Threat Intelligence Group (GTIG) to a series of voice phishing attacks targeting numerous organizations.
Levi's has explicitly stated that no consumer data was affected. However, as a general precaution, individuals with Levi's shop accounts are advised to remain vigilant for any suspicious activity and report it to the company promptly. Further notifications to affected parties will be provided as required by law.






