Levi Strauss & Co. confirms cybersecurity incident following social engineering attack

Levi Strauss & Co. confirms cybersecurity incident following social engineering attack

Levi Strauss & Co. has confirmed that an unauthorised third party accessed and exfiltrated corporate information after using social engineering techniques to gain access to three employees’ company-issued computers.

Levi Strauss & Co. has disclosed a cybersecurity incident in which an unauthorised third party used social engineering techniques to gain access to three employees’ company-issued computers.

According to the company, the incident resulted in access to company files, with preliminary findings indicating that some corporate information was accessed and exfiltrated.

Following detection of the incident, Levi Strauss & Co. initiated its response protocols, implemented containment measures and launched an investigation with support from third-party cybersecurity experts.

The company said its response successfully contained and terminated the unauthorised access. Its investigation remains ongoing.

Based on information currently available, Levi Strauss & Co. said it does not believe any consumer data was affected. The incident has also not caused any interruption to its business operations.

The company said it does not currently believe the incident has had, or is reasonably likely to have, a material impact on its business strategy, operations, financial condition or results.

Levi Strauss & Co. is providing notifications to affected parties and relevant regulators where appropriate and in accordance with applicable law.

Commenting on the incident, Dr Darren Williams, Founder and CEO, BlackFog, said: “An attack on a global brand like Levi Strauss & Co. demonstrates that retailers remain firmly in the crosshairs of cybercriminals. With vast volumes of valuable customer and corporate data at stake, attackers only need to find one way in. Employees remain a prime target, with social engineering and credential phishing capable of turning a single compromised account into a gateway to wider company systems.

“Once an attacker gains access, the clock is already ticking. Their priority is often to identify and exfiltrate valuable data as quickly as possible, either to fuel extortion attempts or sell it on criminal marketplaces. This makes the speed of detection and response critical, but organisations also need to be able to stop data from leaving in real time before it falls into the wrong hands.

“Businesses can no longer build their cybersecurity strategies around the assumption that attackers will never breach their defences. Employee awareness and strong access controls remain essential, but they must be backed by technology that prevents sensitive data from being exfiltrated, even when an attacker has successfully gained access to the network.”

Browse our latest issue

Intelligent CISO

View Magazine Archive