Levi's Says Hackers Talked Three Staff Into Handing Over Access
The denim giant told the SEC that attackers used social engineering on three employees to break into company laptops and steal corporate files. No customer data hit, Levi's says.

Key points
- Levi Strauss & Co. told the U.S. Securities and Exchange Commission that attackers tricked three employees into giving up access to their work computers.
- The company says corporate data was stolen but consumer data was not touched.
- Store operations and online sales kept running normally through the incident.
- Some outlets have linked the attack to UNC6671, a group tied by Google's Threat Intelligence Group to a wave of voice phishing calls hitting hundreds of companies.
- Levi's investigation is still open and it says the incident will not have a material financial impact.
Levi Strauss & Co., the American company behind the 501 jeans, says criminals tricked three of its employees into giving up access to their work laptops, then copied corporate files off those machines.
The company put the details in a filing with the U.S. Securities and Exchange Commission, the U.S. financial regulator that requires public companies to disclose serious incidents to investors.
Levi's says no customer data was taken. Stores kept trading. The website kept selling jeans. First reported by BleepingComputer, the disclosure is short on technical specifics but clear on the entry point: people, not software.
How did the hackers get in?
Through the staff. Levi's says an unknown attacker used social engineering, meaning tricking someone into helping the attacker rather than breaking a system, against three employees. Once those three were fooled, the attacker got onto their company-issued computers and copied corporate information off them.
The filing does not spell out the trick used. But other reporting has linked the intrusion to a group tracked as UNC6671, which Google's Threat Intelligence Group has tied to a recent run of voice phishing (or "vishing") attacks. That is where a caller pretends to be IT support or a colleague and talks the target through steps that hand over their login.
In practice, this is the same playbook that has hit Snowflake customers, MGM, and a long list of others in the last two years. The failure mode here is almost always the same: a convincing phone call, a rushed employee, and a single sign-on session that gets handed over in good faith.
Should Levi's customers be worried?
Probably not, based on what the company has said so far. Levi's states plainly that consumer data was not impacted and that the intrusion was contained before it spread further.
That is the current story. Investigations of this kind can revise upward. If you have a Levi's online account, it is worth doing the boring but useful thing: change the password, turn on multi-factor authentication if you have not, and watch your inbox for password-reset emails you did not ask for.
What did the attackers actually take?
Levi's has said only that "certain corporate information was accessed and exfiltrated." That phrasing usually covers internal documents, employee-related files, or business records, not the payment card and customer databases that live in a separate system.
Here is what the company has confirmed publicly:
| Detail | What Levi's says |
|---|---|
| Method | Social engineering of employees |
| Employees affected | 3 |
| Corporate data stolen | Yes |
| Consumer data stolen | No, per the company |
| Operational disruption | None |
| Financial impact | Not material |
One thing the post-mortem will say, if it looks like most of the ones I read this year: the attackers did not need a zero-day, which is a software flaw the maker didn't know about. They needed a phone and a plausible voice.
Operational takeaway: your help desk is your perimeter now. Treat it accordingly.



