LIVE · cybersecurity feed
Live wire
data breachmedium

Levi Strauss says hackers breached employee computers, accessed corporate data

Levi Strauss & Co. has reported a cybersecurity incident where hackers gained unauthorized access to corporate data by compromising three employee-issued computers through a social engineering attack. The company stated that the breach was contained quickly, business operations were not disrupted, and there is no evidence that consumer data was affected. The investigation into the incident is ongoing, and no attackers have been identified.

zeroday.news ·

Levi Strauss & Co. has confirmed that an unauthorized third party accessed and exfiltrated corporate data after compromising employee computers through a social engineering attack. The iconic apparel manufacturer disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on Friday, August 7th, 2026.

According to the company, the attackers gained access to three company-issued computers. While Levi Strauss did not specify the exact type of corporate data that was taken, it stated that the breach was contained shortly after discovery and did not disrupt business operations. The company also emphasized that there is no evidence to suggest consumer data was affected.

Levi Strauss does not anticipate that the incident will have a material impact on its business strategy, operations, financial condition, or results of operations. The San Francisco-based company, known for its Levi's denim brand, operates nearly 3,300 retail stores globally, employs approximately 19,000 people, and reported $6.3 billion in net revenue last year. Its market capitalization exceeds $9 billion.

The company has not identified the attackers, nor has it disclosed whether ransomware was involved or if a ransom demand was received. No hacking group has publicly claimed responsibility for the incident, and the investigation is ongoing.

This incident follows a trend of increasing cyberthreats targeting retailers. Earlier this week, Dutch luxury department store chain De Bijenkorf reported a cyberattack on a logistics provider that impacted customer orders and potentially exposed customer information. In 2025, British retailers Harrods, M&S, and The Co-op also experienced cybersecurity incidents. Last year, fast-fashion retailer Mango and outdoor clothing brand The North Face disclosed data breaches.

Authorities like the FBI have consistently warned companies about the growing prevalence of social engineering campaigns by cybercriminals, which leverage human interaction to trick individuals into divulging confidential information or granting access to systems.

data breachsocial engineeringlevi strausscorporate data
ShareXLinkedInWhatsAppFacebook

More News

view all →
malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

ai

OpenAI pledges to add Astra security as Anthropic loosens Fable's leash

Or how I learned to stop worrying and love dangerous AI

ai

AI chat bots are sliding into League of Legends friend requests

Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?

security

Meta ordered to pay $942 million over harm to children

A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.

breachcritical

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

icshigh

Ex-NSA Chief Urges Disconnecting Water Controllers from Internet

Following suspected cyberattacks on water systems across at least 12 US states, likely perpetrated by Iran, a former NSA chief has strongly advised that industrial control systems like programmable logic controllers (PLCs) should not be connected to the internet. He emphasized the need for higher cybersecurity standards to defend these critical infrastructure components, noting that Iranian actors have a history and capability for such attacks.