VYPR
breachPublished Aug 7, 2026· Updated Aug 10, 2026· 4 sources

Levi Strauss Discloses Data Breach After Social Engineering Attack on Employee Computers

Levi Strauss & Co. reported a data breach stemming from a social engineering attack that compromised three employee computers, leading to the exfiltration of corporate data.

Iconic American apparel maker Levi Strauss & Co. has disclosed a cybersecurity incident where unauthorized actors gained access to company files after compromising employee computers. The breach, revealed in a filing with the U.S. Securities and Exchange Commission, involved a social engineering attack that successfully targeted three company-issued computers.

According to the filing, the threat actors accessed and exfiltrated certain corporate information from these compromised systems. Levi Strauss has not specified the exact nature of the data taken, stating only that it was "corporate information." The company moved quickly to contain the breach upon discovery, and it has confirmed that business operations were not disrupted.

Levi Strauss emphasized that there is currently no evidence to suggest that consumer data was affected by this incident. The company also stated its belief that the breach will not have a material impact on its business strategy, operations, financial condition, or results. This assessment is based on the current understanding of the scope and nature of the exfiltrated data.

Details regarding the attackers, whether ransomware was involved, or if any ransom demands were made, remain undisclosed. No hacking group has publicly claimed responsibility for the incident, and Levi Strauss indicated that an investigation is ongoing. The company, headquartered in San Francisco, is globally recognized for its Levi's denim brand and operates nearly 3,300 retail stores worldwide, employing approximately 19,000 individuals.

This incident places Levi Strauss among a growing number of retailers facing significant cybersecurity threats. Recently, Dutch department store De Bijenkorf reported a cyberattack impacting its logistics provider, causing delays and potential customer data exposure. Last year, fast-fashion retailer Mango and outdoor brand The North Face also disclosed data breaches, with British retailers Harrods, M&S, and The Co-op experiencing similar cybersecurity events in 2025.

The FBI and other authorities have consistently warned about the escalating prevalence of social engineering campaigns orchestrated by cybercriminals. These attacks often exploit human trust and psychological manipulation to gain initial access to sensitive systems, as appears to be the case with Levi Strauss.

While Levi Strauss has contained the immediate threat and stated no material impact is expected, the incident underscores the persistent risks faced by companies of all sizes. The ongoing investigation will likely shed more light on the specific tactics used and the full extent of the compromised corporate data.

The incident involved a targeted social engineering attack where three employees were tricked into granting access to their company computers. While the attackers exfiltrated corporate files, Levi Strauss confirmed that no consumer data was affected and business operations remain uninterrupted. The company has initiated an investigation with third-party cybersecurity experts and is notifying affected parties and regulators.

Unconfirmed reports suggest that the hacking group UNC6671, known for recent voice phishing (vishing) campaigns, may be involved in the Levi Strauss attack. While Levi Strauss has not disclosed the specific social engineering tactics used or attributed the attack to any particular group, this potential link provides an early indicator of the threat actor's identity and methods.

The new reporting indicates that the social engineering tactics used in the Levi Strauss breach align with a broader campaign tracked by Google researchers, potentially involving the group UNC6671. This campaign has targeted various sectors using phone calls and spoofed login pages to harvest credentials and MFA codes, though it remains unconfirmed if UNC6671 was directly responsible for the Levi's incident.

Synthesized by Vypr AI