Levi Strauss & Co. has confirmed that an unauthorized third party accessed and exfiltrated corporate data after compromising employee computers through a social engineering attack. The iconic apparel manufacturer disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on Friday, August 7th, 2026.
According to the company, the attackers gained access to three company-issued computers. While Levi Strauss did not specify the exact type of corporate data that was taken, it stated that the breach was contained shortly after discovery and did not disrupt business operations. The company also emphasized that there is no evidence to suggest consumer data was affected.
Levi Strauss does not anticipate that the incident will have a material impact on its business strategy, operations, financial condition, or results of operations. The San Francisco-based company, known for its Levi's denim brand, operates nearly 3,300 retail stores globally, employs approximately 19,000 people, and reported $6.3 billion in net revenue last year. Its market capitalization exceeds $9 billion.
The company has not identified the attackers, nor has it disclosed whether ransomware was involved or if a ransom demand was received. No hacking group has publicly claimed responsibility for the incident, and the investigation is ongoing.
This incident follows a trend of increasing cyberthreats targeting retailers. Earlier this week, Dutch luxury department store chain De Bijenkorf reported a cyberattack on a logistics provider that impacted customer orders and potentially exposed customer information. In 2025, British retailers Harrods, M&S, and The Co-op also experienced cybersecurity incidents. Last year, fast-fashion retailer Mango and outdoor clothing brand The North Face disclosed data breaches.
Authorities like the FBI have consistently warned companies about the growing prevalence of social engineering campaigns by cybercriminals, which leverage human interaction to trick individuals into divulging confidential information or granting access to systems.






