Levi Strauss & Co. disclosed that attackers used a social engineering attack against three employees, compromising company-issued computers and gaining unauthorized access to corporate files. The company said certain corporate information was accessed and exfiltrated, but it contained the intrusion quickly, reported no disruption to business operations, and said there is no evidence that consumer data was affected.
The incident was disclosed in an SEC filing, where Levi Strauss said it does not currently expect the breach to materially affect its business, operations, financial condition, or results. The investigation remains ongoing, no threat actor has publicly claimed responsibility, and the company said it will provide additional notifications to affected parties if required; some reporting has linked the activity to UNC6671, a cluster previously associated by Google Threat Intelligence Group with voice phishing campaigns.

See attribution, scope, and your downstream exposure.
3 events from the most recent confirmed update back to the earliest known activity.
Levi Strauss & Co. disclosed the cybersecurity incident on Friday in a filing with the U.S. Securities and Exchange Commission. The company said the investigation is ongoing and that it does not currently expect the incident to materially affect its business or financial condition.
Following discovery of the social-engineering intrusion, Levi Strauss said it notified law enforcement and engaged external cybersecurity experts while activating incident response and business continuity procedures. The company also said it would notify affected parties and regulators as appropriate.
Levi Strauss & Co. said an unauthorized third party used social engineering against three employees, gained access to three company-issued computers, and exfiltrated certain corporate information. The company said it quickly contained the intrusion, saw no business disruption, and found no evidence that consumer data was affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
13 references tracked. Mallory keeps watching after this page renders.
xakep.ru
Open sourcecysecurity.news
Open sourceteiss.co.uk
Open sourcetheregister.com
Open sourcedarkwebinformer.com
Open sourcebleepingcomputer.com
Open sourcetherecord.media
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.