Levi Strauss & Co. has confirmed a cybersecurity incident in which an unauthorized third party used social engineering techniques to gain access to three employees’ company-issued computers and steal corporate information.
The apparel company disclosed the incident in an August 7 Form 8-K filing with the U.S. Securities and Exchange Commission, stating that its investigation remains ongoing. Levi Strauss said its preliminary findings indicate that corporate data was accessed and exfiltrated, but that consumer information was not affected.
Three employee computers compromised
According to the filing, the attackers used social engineering techniques that resulted in unauthorized access to three company-issued computers belonging to Levi Strauss employees. The company did not disclose the specific social engineering method used, how the employees were approached, or what credentials or access mechanisms may have been compromised.
After detecting the activity, Levi Strauss activated its incident response procedures, implemented containment measures, launched an investigation, and engaged third-party cybersecurity specialists. The company said its response successfully terminated the unauthorized access.
The disclosure does not specify when the intrusion began or how long the attackers maintained access to the affected computers.
Corporate information was exfiltrated
Levi Strauss confirmed that certain corporate information was accessed and exfiltrated from its environment. The company has not publicly detailed what types of corporate records were taken, how much information was stolen, or whether the data included employee, financial, operational, or intellectual property information.
Importantly, the company said its investigation currently indicates that no consumer data was affected. Levi Strauss also reported no disruption to its business operations as a result of the incident.
The company added that it will provide notifications to affected parties and regulators where required as the investigation progresses.
No threat actor identified
Levi Strauss has not publicly attributed the attack to a specific threat actor, ransomware operation, or data extortion group. The SEC filing also does not indicate whether the company received an extortion demand following the theft of corporate information.
Some media reports have linked the incident to the broader wave of social engineering and voice phishing attacks that have recently targeted large enterprises. However, Levi Strauss has not confirmed any attribution, and no threat group has publicly claimed responsibility for the attack.
Because the company specifically identified social engineering as the initial access method, the incident highlights the continued effectiveness of attacks that target employees directly rather than software vulnerabilities.
Business operations unaffected
Based on information available as of the filing, Levi Strauss said it does not believe the incident has had, or is reasonably likely to have, a material impact on its business strategy, operations, financial condition, or financial results.
The investigation remains active, meaning the scope of the stolen corporate information could change as forensic work continues. Levi Strauss has not disclosed whether additional employee systems or corporate accounts were accessed beyond the three company-issued computers identified in its initial findings.
BreachNews will update this article if Levi Strauss releases additional details regarding the stolen data, the social engineering techniques used, or the identity of the attackers.











