Levi Strauss & Co.
Incident posture
Linked entities
- Victim
- Levi Strauss & Co.
- Threat actors
- 0 actors
- Sources
- 4 sources
Timeline
Summary
Levi Strauss & Co disclosed a cybersecurity breach resulting from a social engineering attack that compromised three employees’ company‑issued computers and allowed an unauthorized third party to access certain corporate data. The company said the intrusion did not affect customer information, did not disrupt operations, and is not expected to have a material impact, while containment measures have been applied and the attackers have been evicted from the systems. An ongoing investigation is examining the scope of the accessed data, and the company noted the incident fits a broader pattern of phone‑based social engineering campaigns targeting multiple firms across industries.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
Levi Strauss & Co. disclosed a cybersecurity incident on August 8 2026 through a statement to KSLNewsRadio in which the company said an unauthorized third party had gained access to its systems via a social engineering attack that targeted three employees. The disclosure noted that the company had implemented containment measures and launched an investigation, with preliminary findings indicating that certain corporate information had been accessed and extracted. On August 10 2026 Levi Strauss filed a Form 8‑K with the U.S. Securities and Exchange Commission providing further details, stating that the incident resulted from social engineering and affected three employees’ company‑issued computers, and that the company’s immediate response and containment actions had led to the attackers’ eviction from those compromised systems. The filing also said that, based on the preliminary findings of the ongoing investigation, the company believed that certain corporate information had been accessed and exfiltrated as a result of the incident, but that no customer data appeared to have been stolen. Levi Strauss emphasized that the incident had not caused any interruption in its business operations and that it did not believe the event had had, or was reasonably likely to have, a material impact on its operations or financial results. The company did not disclose the identity of the threat actor, whether any extortion demands had been made, or the specific type of social engineering technique used in the attack.
The social engineering attack described in the disclosures involved unauthorized access to certain corporate data stored on the three affected employees’ company‑issued computers, though the articles do not specify the exact categories of corporate information that were accessed or exfiltrated. The company’s statements indicate that the breach was confined to those employee workstations and did not extend to customer‑facing systems or databases containing personal data of consumers. The containment measures referenced in the August 8 KSLNewsRadio report and the August 10 SEC filing succeeded in removing the attackers from the compromised computers, although the articles do not detail the technical steps taken to achieve eviction. Levi Strauss said it had launched an investigation into the incident, with the investigation remaining ongoing at the time of the disclosures, and that it had not yet determined whether any further actions beyond containment would be required. The company also noted that it had not observed any evidence that the stolen information had been publicly posted or used for identity theft or fraud, although this observation was not explicitly made in the Levi Strauss sources; it reflects the cautious language used in similar disclosures from other firms in the same reporting period.
In describing the broader threat environment, the August 8 KSLNewsRadio article cited Google and internet intelligence data reviewed by Reuters, which showed that ransom‑seeking hackers who use phone calls to compromise victims had targeted dozens of prominent financial institutions and other businesses over the past month. The same data indicated that cybercriminals had created digital traps for more than 200 companies in the preceding five weeks, with Levi Strauss specifically named among those organizations. The article also noted that Uber Freight had earlier in the month announced that it was investigating a cybersecurity incident involving unauthorized access to its systems, suggesting a parallel trend affecting multiple companies. Levi Strauss’s own statements in the August 10 Form 8‑K filing did not attribute the attack to any particular group or motive, nor did they confirm that the phone‑call‑based social engineering tactic described in the Reuters‑cited intelligence was the exact method used against the company, but the temporal overlap and the mention of Levi Strauss in the threat‑intelligence report situate the incident within a wider campaign of phone‑based social engineering aimed at corporate targets.
Levi Strauss’s public communications emphasized that the incident had not disrupted its day‑to‑day operations and that the company continued to conduct business as usual. The August 10 SEC filing explicitly stated that the company had not experienced any interruption in business operations as a result of the incident and that, based on its assessment, the event was not expected to have a material impact on its financial condition or results of operations. The company also noted that it had raised its annual net sales forecast the previous month, expressing confidence that demand for its premium denim products would remain resilient among higher‑income consumers, although this forecast adjustment is presented as a separate business development rather than a direct consequence of the cybersecurity event. Throughout the disclosures, Levi Strauss refrained from providing speculative details about the attackers’ identity, potential future risks, or the precise nature of the exfiltrated corporate information, limiting its remarks to the facts confirmed by its preliminary investigation and the containment actions already taken.
The narrative of the Levi Strauss & Co. cybersecurity incident, as derived solely from the provided sources, consists of a social engineering compromise targeting three employee workstations, the subsequent access and exfiltration of certain corporate data, rapid containment that expelled the attackers, an ongoing investigation that has so far found no evidence of customer‑data theft or operational disruption, and the company’s assessment that the event is unlikely to produce a material financial effect, all situated within a contemporaneous increase in phone‑call‑based social engineering attempts against numerous corporations.
Sources
Sources available to members: 4 sources.