Levi Strauss & Co disclosed on Friday that a cyberattack resulting from social engineering compromised corporate data stored on three employees’ company-issued computers.
In a Form 8-K filed with the US Securities and Exchange Commission, the denim company said its immediate response and containment actions evicted the attackers from the affected machines.
Based on preliminary findings, Levi Strauss believes certain corporate information was accessed and exfiltrated during the incident. The company says no customer data appears to have been stolen, operations were not interrupted, and the breach is not expected to have a material impact.
The investigation is ongoing. Levi Strauss has not identified who was behind the attack, disclosed the type of social engineering used, or said whether any extortion demands were received.
Unconfirmed reports suggest possible involvement of UNC6671, the hacking group behind a string of recent voice phishing campaigns that has been linked to several corporate compromises. SecurityWeek has contacted the company for additional detail.
The disclosure follows a wave of social-engineering-driven intrusions into US companies, and analysts note that mailbox and desktop access of this kind is frequently used to monitor communications, redirect payments, or stage follow-on attacks even when exfiltration is not immediately visible.
Enterprises should treat the incident as a reminder that credential phishing and vishing remain primary entry vectors, and that endpoint telemetry plus fast credential rotation are the practical first-line defenses when an account compromise is suspected.
