Levi Strauss & Co. (Levi’s) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines.
The company has disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC), saying that its response was sufficiently quick to prevent the compromise of consumer data.
“Based on preliminary findings from the Company’s investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident,” Levi’s says.
“As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, and that no consumer data was impacted.”
The company added that it has not experienced any interruption in business operations as a result of the incident.
Levi’s clothing giant has 19,000 employees and an annual revenue of $6.3 billion, best known for its signature 501-line jeans.
The company operates at least 3,300 stores worldwide, and its products can also be found in numerous third-party retail shops, both “brick and mortar” and online.
The firm says it recently detected a cybersecurity incident in which an unknown attacker social-engineered three of its employees, resulting in the breach of company-issued computers.
The investigation launched in response to the incident remains ongoing, and additional notifications will be provided to affected parties as required.
Based on the findings of the investigation to date, Levi’s does not believe the incident will have a material impact on its business or financial position.
Levi’s also noted that it has not experienced any operational disruptions as a result of this breach.
BleepingComputer could not identify online any threat actors claiming the attack on Levi’s.
However, some media outlets have linked this incident to UNC6671, which Google’s Threat Intelligence Group (GTIG) associated with a recent wave of voice phishing attacks targeting hundreds of organizations.
Although Levi’s stated that no customer data was impacted, until more information becomes available, holders of Levi’s shop accounts should monitor for suspicious activity and promptly report it to the firm.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Man gets six years for hacking 750 women’s Snapchat accounts
Webinar tomorrow: Why modern email attacks require a new approach to defense
Healthtech firm Xolis suffers data breach impacting 1.4 million people
Webinar: How behavioral AI stops phishing and account takeovers
Unlimited Technology Systems breach impacts 3.8 million people
Hackers run khunt post-exploitation toolkit from Oracle database
Ransom Cartel ransomware creator sentenced to 16 years in prison
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
See how real inboxes, fake stores and AI scams shaped H1 2026 cyber threats
AI is a data-breach time bomb: Read the new report
See how Skyhigh Security’s patent-pending approach secures every browser session without costly and clunky enterprise browser replacements.
Spend four hours inside a fully-simulated underground with DARKROOM.
Webinar: Shadow AI in 2026 (and how attackers are taking advantage)
Terms of Use – Privacy Policy – Ethics Statement – Affiliate Disclosure
Read our posting guidelinese to learn what content is prohibited.


