LIVE · cybersecurity feed
Live wire
security

Levi Strauss & Co. says hackers stole corporate data in cyberattack

Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]

zeroday.news ·

Levi Strauss & Co. has confirmed that corporate data was stolen in a recent cyberattack that leveraged social engineering against three of its employees. The apparel company disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), stating that its rapid response prevented any compromise of consumer data.

According to Levi's, the attackers used social engineering tactics to gain unauthorized access to company-issued computers belonging to the three employees. This access led to the exfiltration of certain corporate information. The company, known for its 501-line jeans and operating over 3,300 stores globally, has an annual revenue of $6.3 billion and approximately 19,000 employees.

The investigation into the breach is ongoing. However, Levi's has stated that it does not believe the incident will materially impact its business operations or financial standing, and no operational disruptions have been reported. The company also emphasized that its swift containment efforts successfully terminated the unauthorized access.

While Levi's has not publicly identified the threat actors responsible, some reports have speculated a connection to UNC6671. This group has been linked by Google's Threat Intelligence Group (GTIG) to a series of voice phishing attacks targeting numerous organizations.

Levi's has explicitly stated that no consumer data was affected. However, as a general precaution, individuals with Levi's shop accounts are advised to remain vigilant for any suspicious activity and report it to the company promptly. Further notifications to affected parties will be provided as required by law.

ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

breach

Hackers Impersonate IT Support to Breach Leading Financial Companies

Hackers used fake IT help desks to steal MFA credentials, targeting over 200 firms, including major financial companies. A hacking campaign operating under names including Redact, Pink, Falcon, and Helix has built credential-stealing websites targeting employees at Blackstone, Bridgewater Associates, Apollo Global Management, Bain Capital, KKR, TPG, CME Group, Clearlake Capital, and Moody’s, among

vulnerability

N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands

Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again

ai

Irregular, firm behind AI hacking incidents, won't say if there were more

A spokesperson said Irregular’s investigation into what happened with Anthropic, OpenAI and Meta's AI models was ongoing and that they could not “go into further details.”

data center technology

In Other News: AI Slop Limits Apple Bounties, North Carolina Port Attacks, Hackers Target Wall Street

Several cybersecurity incidents are highlighted, including a ban on Chinese data center technology, a supply chain attack on QuickFox VPN, and a phishing breach at IEH Corporation. Additionally, AI-generated content may be impacting Apple's bug bounty program, and a North Carolina port experienced an attack, alongside broader targeting of Wall Street.

security

North Carolina Ports confirms cyberattack disrupting operations

The North Carolina Ports Authority has confirmed that a cyberattack disrupted IT systems and slowed operations at Port of Wilmington, Port of Morehead City, and Charlotte Inland Port. [...]