Levi Strauss & Co. Hit by Social Engineering Attack, Corporate Data Exfiltrated
**Levi Strauss & Co.** (Leviβs) has disclosed a cybersecurity incident where social engineering tactics were used to compromise three employee systems, leading to the exfiltration of corporate data. While the company maintains no consumer data was impacted and operations remain uninterrupted, the incident highlights the persistent threat of sophisticated phishing attacks.

**Levi Strauss & Co.**, the iconic denim manufacturer, recently filed with the U.S. Securities and Exchange Commission (**SEC**) to report a cybersecurity breach. The incident involved unknown attackers using social engineering to gain unauthorized access to and steal corporate data from three employee-issued computers.
### Attack Details and Company Response
According to the filing, the company's preliminary investigation indicates that "certain corporate information was accessed and exfiltrated." However, **Leviβs** emphasized that its rapid response efforts successfully contained and terminated the unauthorized access, preventing any compromise of consumer data.
The global apparel giant, with 19,000 employees and annual revenues of $6.3 billion, confirmed that the incident has not caused any interruption to its business operations. The investigation into the full scope of the breach is ongoing, and further notifications will be provided to affected parties as required by law.
### Potential Link to UNC6671
While **Leviβs** has not publicly identified the threat actor, some media outlets have drawn a potential link to **UNC6671**. This group has been associated by **Google's Threat Intelligence Group** (**GTIG**) with a recent surge in voice phishing, or 'vishing,' attacks targeting hundreds of organizations, particularly within the hedge fund sector.
### Implications for IT Security Professionals and Users
This incident serves as a critical reminder for IT security professionals about the evolving sophistication of social engineering attacks. Even large, well-resourced organizations like **Leviβs** are not immune to these tactics, which exploit human vulnerabilities rather than purely technical ones.
For privacy-conscious users, while **Leviβs** states no customer data was impacted, the incident underscores the importance of vigilance. Account holders with **Leviβs** should remain alert for any suspicious activity and report it promptly to the company.
Organizations must continue to invest in robust employee training programs, multi-factor authentication, and advanced threat detection systems to defend against these persistent and increasingly targeted social engineering campaigns.