Levi Strauss Breach Began With Social Engineering of 3 Employees

Levi Strauss says hackers socially engineered three employees and stole corporate data, highlighting the growing threat of identity-based attacks.

Aug 10, 2026
3 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Levi Strauss said hackers used social-engineering tactics to compromise three employees, gain unauthorized access to company systems, and steal corporate data.

The company, according to Reuters, has not disclosed what information was taken or whether customer data was affected, and said the incident remains under investigation.

The breach comes amid a broader wave of attacks relying on employee impersonation, phishing, and credential theft. Reuters reported that attackers built customized phishing infrastructure targeting hundreds of organizations, raising the possibility that the Levi Strauss incident is connected to a wider campaign focused on gaining trusted access to corporate systems.

Current known and unknowns

Levi Strauss reported the incident in a Form 8-K filed with the U.S. Securities and Exchange Commission (SEC) on Aug. 7, giving a more precise account. The filing says an unauthorized third party used social-engineering techniques to gain access to the company-issued computers of three employees. 

The company says it contained the unauthorized access, launched an investigation, and hired outside cybersecurity experts. Levi Strauss also said customer data was not affected and that the incident did not disrupt business operations.

Several important details remain unknown. The company has not disclosed what corporate information was stolen, how much data was exfiltrated, when the intrusion began, or exactly how the employees were deceived. Levi Strauss said its investigation remains ongoing and that it will notify affected parties and regulators where appropriate.

Levi Strauss appears to be one of many

At first glance, Levi Strauss’ cyber incident looks like any other cyberattack. But the timing argues otherwise. 

Reuters reported that hackers had attempted to breach major Wall Street firms including Point72, Two Sigma and Citadel, with the attacks involving phone calls designed to lure employees into granting access or revealing sensitive information.

In a separated report, Reuters cited Google’s findings revealing that the campaign extended well beyond financial firms. Attackers had targeted other businesses, while technical analysis identified Levi Strauss, Uber and Zillow among organizations whose employees were targeted.

Advertisement

The attackers also created customized phishing traps for more than 200 organizations in about five weeks.

Google’s analysis linked several hacker aliases to the campaign and found that the attackers were using fake IT help desk identities, spoofed phone numbers, and fraudulent websites to obtain employee passwords and two-factor authentication codes. 

The bigger problem is trusted access

Levi Strauss’ breach points to a security problem that is harder to solve. Once an employee is compromised, the attacker may be able to operate through legitimate accounts, making malicious activity harder to distinguish.

That raises the stakes for companies. Identity monitoring, strong authentication, device controls, and rapid detection of unusual account activity become just as important as perimeter defenses.

For Levi Strauss, the immediate question is what information the attackers obtained; for other companies, the warning is broader. A well-protected network can still be exposed when attackers convince an authorized employee to open the door.

Other News: A hacker tied to the 2024 Snowflake attacks pleaded guilty after a campaign that exposed data belonging to at least 100 million people. 

Joseph Chisom Ofonagoro

Joseph is a Technical Writer with about 3 years of experience in the industry, also advancing a career in cyber threat intelligence. He is passionate about the responsible use of technology, a passion that led him into cybersecurity. As an undergrad, he leads a novel community of technology enthusiasts at his school, NOUN, where he guides and shares resources for beginners in tech. His writing experience includes a diverse range of topics, from consumer tech to startups to tutorials. Additionally, he periodically shares case studies and research reports on cybersecurity on his social media pages.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。