Overview
- Levi Strauss disclosed in an SEC filing on Friday that attackers used social engineering on three employees to gain unauthorized access to company systems.
- Based on preliminary findings, the company believes certain corporate information was accessed and exfiltrated from the compromised machines.
- Levi Strauss says its rapid response contained and terminated the access, that no consumer data was affected, and that business operations have not been disrupted.
- External intelligence reviewed by reporters ties similar phone-based attacks to a wider campaign that targeted more than 200 firms recently and that some researchers label UNC6671, though attribution is not confirmed.
- The incident highlights growing risks from voice‑phishing for employees and companies and could prompt wider industry alerts, added controls for phone-based verification, and more regulatory disclosures to investors.