"Based on preliminary findings from the Company’s investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident," Levi Strauss & Co. said in a filing with the U.S. Securities and Exchange Commission.
Levi Strauss & Co.'s disclosure to the SEC
Levi Strauss & Co. disclosed the incident in an SEC filing, describing a recent cybersecurity intrusion that the company says it detected and moved to contain rapidly. In that filing the company stated that, as of the date of the disclosure, its rapid response efforts "successfully contained and terminated the unauthorized access, and that no consumer data was impacted." Levi’s said the investigation is ongoing and that it will provide additional notifications to affected parties as required.
How the intrusion occurred: social engineering of three employees
The company attributed the breach to social engineering directed at three employees, which allowed an unknown attacker to gain access to and steal corporate data stored on company-issued machines. Levi’s said the attacker targeted those three employees specifically, resulting in a breach of the devices they used for work. The filing characterizes the findings as preliminary.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleScope, business footprint, and immediate operational impact
Levi’s told regulators and investors it has not experienced any interruption in business operations as a result of the incident. The disclosure notes the scale of the company’s operations—about 19,000 employees, roughly $6.3 billion in annual revenue, and at least 3,300 stores worldwide—while reiterating that, based on current findings, the company does not expect the incident to have a material impact on its business or financial position. The filing also emphasized that no consumer data were impacted according to the company’s preliminary investigation.
Attribution reporting and external coverage
BleepingComputer reported that it could not find any online claims by threat actors taking credit for the attack. The outlet also noted that some media organizations have linked Levi’s incident to UNC6671, a group that Google’s Threat Intelligence Group associated with a recent wave of voice phishing attacks that targeted hundreds of organizations. Levi’s own public statements did not attribute the attack to a specific group in the SEC filing, describing the perpetrator as "unknown."
What this means for Levi's account holders, security teams, and investigators
- Levi's shop-account holders: The company advised account holders to monitor for suspicious activity and to promptly report any concerns to Levi’s, even though it stated no customer data were impacted as of the filing date.
- Security teams and incident responders: Levi’s credited "rapid response efforts" with containing and terminating access; the company has launched an ongoing investigation into what corporate information was exfiltrated and how and will provide additional notifications as required.
- Investigators and regulators: The SEC filing signals that formal disclosure and follow-up notifications are part of Levi’s response; the investigation remains open and the company described current findings as preliminary while also saying it does not expect a material business impact.
The record released so far is precise about method and immediate consequence: social engineering targeted three employees, corporate data was accessed and exfiltrated, and Levi’s says it halted the intrusion before consumer data were affected or operations were interrupted. What remains to be established in the ongoing probe are the full contents of the data taken, whether any additional accounts or systems were touched, and whether the links some outlets draw to UNC6671 and a broader voice-phishing wave will be borne out by forensic evidence.
Read the original report: BleepingComputer — Levi Strauss & Co. says hackers stole corporate data in cyberattack




