Levi's Says Hackers Talked Three Staff Into Handing Over Access

The denim giant told the SEC that attackers used social engineering on three employees to break into company laptops and steal corporate files. No customer data hit, Levi's says.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
An office worker at a desk receiving a phishing email or message on their computer, with a shadowy figure visible through the monitor representing the attacker
Share

Key points

  • Levi Strauss & Co. Told the U.S. Securities and Exchange Commission that attackers tricked three employees into giving up access to their work computers.
  • The company says corporate data was stolen but consumer data was not touched.
  • Store operations and online sales kept running normally through the incident.
  • Some outlets have linked the attack to UNC6671, a group tied by Google's Threat Intelligence Group to a wave of voice phishing calls hitting hundreds of companies.
  • Levi's investigation is still open and it says the incident will not have a material financial impact.

Levi Strauss & Co., the company behind the 501 jeans and 19,000 employees and $6.3 billion in annual revenue, says criminals tricked three of its staff into surrendering access to their work laptops, then copied corporate files off those machines.

The company put the details in a filing with the U.S. Securities and Exchange Commission, the financial regulator that requires public companies to disclose serious incidents to investors. First reported by BleepingComputer, the disclosure is short on technical specifics but clear on the entry point: people, not software.

How did the hackers get in?

Through the staff. An unknown attacker used social engineering, meaning tricking someone into helping rather than breaking a system, against three employees. Once fooled, those three handed over access to their company-issued computers and the attacker copied corporate information off them.

The filing does not spell out the trick used. Other reporting has linked the intrusion to UNC6671, which Google's Threat Intelligence Group has tied to a recent run of voice phishing, or vishing, attacks. That is where a caller pretends to be IT support and talks the target through steps that surrender their login. We covered UNC6671 a day before this disclosure, when the group was traced to help-desk phone scams hitting Point72, Citadel and other hedge funds.

The failure mode here is almost always identical: a convincing caller, a rushed employee, and a single sign-on session handed over in good faith. No zero-day required.

Should Levi's customers be worried?

Probably not, based on what the company has said so far. Levi's states plainly that consumer data was not impacted and that the intrusion was contained before it spread further.

That is the current story. Investigations of this kind can revise upward. If you have a Levi's online account, change the password, turn on multi-factor authentication if you have not, and watch for password-reset emails you did not request.

What did the attackers actually take?

Levi's has said only that "certain corporate information was accessed and exfiltrated." That phrasing typically covers internal documents or business records, not payment card and customer databases that sit in separate systems.

Here is what the company has confirmed publicly:

Detail What Levi's says
Method Social engineering of employees
Employees affected 3
Corporate data stolen Yes
Consumer data stolen No, per the company
Operational disruption None
Financial impact Not material

The post-mortem will almost certainly say what most of the ones I have read this year say: no exotic vulnerability, no sophisticated implant. A phone and a plausible voice.

Your help desk is your perimeter now. Treat it accordingly.

© 2026 Threat Vectr