Hackers managed to gain access to Levi's, and just three computers sufficed.
Levi Strauss has revealed a data breach that did not stem from any software vulnerability. Attackers exploited social engineering tactics to access the work computers of three employees, subsequently stealing corporate data. The company outlined the incident in a regulatory filing with the SEC on August 7. According to the filing, intruders accessed and retrieved "certain corporate information," though the specific details were not disclosed.
Carly Page from The Register reported on the announcement on Monday. Levi's detected the breach, initiated an incident response, enlisted external cybersecurity experts, and revoked access to the affected systems.
Details highlighted in the filing, as well as omissions, are notable. The disclosure consists of a few brief paragraphs under Item 8.01, a section designated for events not covered by other items. The general counsel, David Jedrzejek, signed off on it.
The reassurances provided are specific. An initial investigation found that no consumer data was involved, and operations were not disrupted. The company believes the incident is unlikely to have a significant impact on its business or financial results.
Conversely, the gaps in the disclosure are equally notable. Levi’s has not specified what data the intruders accessed or their identities. There has been no mention of any ransom demands, which would elevate the situation from theft to data extortion.
A broader campaign rather than an isolated incident
Reuters has reported that Levi’s is part of a larger trend, with over 200 companies having been targeted in the past five weeks by groups that seek ransoms and rely on social engineering rather than technical exploits. Google researchers are monitoring several of these groups under the designation UNC6671. Their methodology is consistent: they contact employees on their personal mobile phones, impersonate a colleague or IT support, and direct the target to a fake login page.
This page collects both the password and the one-time code, rendering multi-factor authentication ineffective, as it simply becomes another piece of information to relay aloud. Google assigns numerical designations to these groups until they can identify them. The same approach was used for UNC5792, which deceived users into linking their Signal accounts to an unknown device.
The groups shift their targets frequently. According to Google, these attackers have previously focused on sectors such as manufacturing, healthcare, insurance, technology, and hospitality. Recently, financial and legal firms have also been affected.
No one has linked the Levi’s breach to any specific group
There is currently no connection established to UNC6671. The Register explicitly notes that there is no confirmation that this group was responsible for the breach, nor has any threat actor claimed responsibility publicly. Levi’s has not named any suspects either. It is standard practice to avoid naming culprits in an ongoing investigation, which is also why the reference to a campaign should remain speculative rather than conclusive.
Consumer brands have faced a challenging year in this regard. Estée Lauder suffered a breach through an Oracle business system, resulting in stolen corporate data. Others have experienced worse outcomes. A ransomware attack on Coca-Cola’s Fairlife halted production in the U.S., while Levi's maintains that its operations continued without interruption.
The distinction between these two outcomes may not be as clear-cut as it appears. Levi’s managed to identify the breach quickly, and the same tactics used on a personal phone could just as easily target a production line. However, the company has yet to clarify how much data was compromised during the incident.
Other articles
Hackers managed to gain access to Levi's, and just three computers sufficed.
Levi Strauss reports that attackers employed social engineering tactics to access the computers of three employees and steal corporate data. There was no involvement of consumer data.
