Skip to main content
Emerging ThreatsData Breaches

Levi's Probes Data Breach After Social Engineering Attack

Business office setting with computers on a desk and employees in the background.

"Certain corporate information," Levi Strauss said in a regulatory filing, was taken after attackers used social engineering to access three employees' work computers — a brief description that left as many questions open as it answered.

Levi Strauss: what the company reported

The jeans maker said it detected the intrusion, activated its incident response procedures, retained outside cybersecurity experts and cut off the unauthorized access. Levi Strauss confirmed its investigation remains ongoing and said its preliminary findings indicate no consumer data was affected. The company also said the attack caused no disruption to operations and, based on what it knows so far, is not expected to have a material impact on the business. It added that affected parties and regulators will be notified where required. The filing did not specify exactly what information was taken, nor did the company say whether anyone tried to extort it.

Technique used: social engineering via personal mobiles and spoofed logins

Reporting tied Levi's intrusion to a broader campaign in which attackers phoned employees on their personal mobile phones while posing as colleagues or IT support staff. According to the reporting, the callers then directed targets to spoofed login pages designed to harvest credentials and multi-factor authentication codes. In Levi's case, the intruders gained access to three employees' work computers and exfiltrated what the company described only as "certain corporate information."

Google researchers and the UNC6671 umbrella

Reuters reported that Google researchers have been tracking several crews involved in the wider campaign and believe those crews may sit under an umbrella group dubbed UNC6671. The reporting noted there is no confirmation that UNC6671 was behind the successful Levi's intrusion. The assessment by those researchers describes a campaign of ransom-seeking hackers using the old-school social engineering approach of voice-based contact and credential harvesting via spoofed pages.

Who the campaign has targeted

Levi Strauss was reported to be among more than 200 organizations targeted over the past five weeks, according to the same reporting. The campaign's targets included financial and legal firms—categories singled out for holding information that can be particularly useful in extortion schemes. The reporting also said the attackers have previously gone after organizations in manufacturing, healthcare, insurance, technology and hospitality.

What this means for technologists, regulators, and consumers

  • Technologists and security teams: the incident underlines that phone-based social engineering plus spoofed login pages remain an active tactic; Levi Strauss' response—detecting the intrusion, invoking incident response, and engaging outside experts—illustrates defensive steps companies reported taking in this case.
  • Regulators and compliance officers: Levi Strauss indicated that affected parties and regulators will be notified where required, signaling ongoing obligations that follow notification rules when corporate information is exfiltrated.
  • Consumers and employees: Levi Strauss' preliminary statement that no consumer data was affected is the only customer-facing assurance provided so far; the company has not published further details about what was taken or whether extortion was attempted.

For now, Levi Strauss appears to have contained the breach before attackers could "get any deeper into its pockets," as the reporting put it — but the record remains incomplete. The company continues an investigation, external researchers have tied the method to a larger campaign affecting more than 200 targets, and the specifics of what was exfiltrated and whether extortion followed have not been disclosed. Those open points will determine how consequential this episode proves to be for Levi Strauss and for others caught in the rounds of voice-based credential harvesting.

Original story (The Register / Reuters reporting)