Levi Strauss & Co. has disclosed a cybersecurity incident in which an unidentified attacker manipulated three employees and gained access to company-issued computers. The intrusion resulted in corporate information being stolen, although the clothing company says its investigation has so far found no evidence that customer data was affected.
Levi’s disclosed the breach in a filing with the U.S. Securities and Exchange Commission. According to the company, its security team responded quickly enough to remove the unauthorized access before the incident developed into a wider compromise.
The attack began with social engineering rather than the exploitation of a publicly disclosed software vulnerability. Three Levi’s employees were targeted, and the attackers subsequently obtained unauthorized access to their work computers.
Levi’s preliminary investigation determined that corporate information stored on the affected systems was accessed and exfiltrated. The company has not publicly detailed what specific internal files or records were taken.
Importantly, the investigation has not found evidence that consumer information was exposed. Levi’s also reported that the breach did not interrupt its operations.
The investigation remains active, meaning the company’s assessment could change as forensic work continues. Levi’s said it will provide notifications to affected parties where required.
Based on what has been established so far, the company does not expect the incident to have a material effect on its business operations or financial condition.
The attack demonstrates how employee devices can provide an alternative route into a corporate environment. Instead of having to find and exploit a technical vulnerability, attackers using social engineering attempt to convince employees to take actions that ultimately provide unauthorized access.
Exactly what method was used against the three Levi’s employees has not been publicly disclosed. The company has not said whether the attackers contacted them by telephone, email, messaging services or another channel. It has also not disclosed what information the employees were persuaded to provide or what actions allowed the compromise to occur.
For Levi’s, the immediate damage appears to have been confined to corporate information. The company says consumer information was not impacted, its business continued operating normally, and unauthorized access was terminated.
The full scope of the breach, however, remains under investigation. Levi’s has not revealed how long the attackers had access to the compromised computers, how much information was removed or what categories of corporate data were stolen.
Until that investigation is completed, the SEC disclosure provides only a preliminary picture of the incident. What is currently established is that three employees were successfully targeted through social engineering, company computers were compromised, and corporate information was exfiltrated before Levi’s contained the intrusion.
