Skip to main content

Levi Strauss & Co. Corporate Data Stolen via Social Engineering

4 min read Runtime Rebel Intel
Primary source: bleepingcomputer.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Corporate data from Levi Strauss & Co. was stolen, though no consumer data was compromised in the incident.
  • Company-issued computers of three employees were breached due to successful social engineering tactics.
  • Implement advanced anti-phishing training and multi-factor authentication across all corporate systems.

Advertisement

Levi Strauss & Co., the global apparel company, has publicly disclosed a cybersecurity incident that resulted in the exfiltration of corporate data. The breach, which involved social engineering targeting three employees, was detailed in a filing with the U.S. Securities and Exchange Commission (SEC), according to BleepingComputer. The company emphasizes that its rapid response successfully contained the unauthorized access and prevented any compromise of consumer data or disruption to business operations.

Technical Details of the Levi Strauss Social Engineering Breach

The incident involved an unknown attacker successfully employing social engineering tactics against three Levi Strauss & Co. employees. This enabled the threat actor to gain unauthorized access to and steal corporate information stored on their company-issued machines. While the specific nature of the exfiltrated corporate data has not been fully disclosed, the company has stated that preliminary findings indicate certain corporate information was accessed and removed from their systems.

While Levi’s has not attributed the attack, some media outlets have linked this incident to UNC6671, a group that Google’s Threat Intelligence Group (GTIG) has associated with recent voice phishing campaigns targeting numerous organizations. Understanding identifying UNC6671 social engineering tactics is crucial for security teams, although official attribution from Levi Strauss & Co. is pending further investigation. The company’s quick response is credited with limiting the scope of the breach, particularly in safeguarding consumer data, which remains a primary concern for any retail entity.

Impact and Business Implications

Despite the data exfiltration, Levi Strauss & Co. has affirmed that the incident has not caused any interruption to its business operations. Furthermore, the company does not anticipate a material impact on its business or financial position as a result of the breach. This assessment is significant, particularly given Levi’s substantial global presence, with 19,000 employees and over 3,300 stores worldwide.

However, the breach underscores the persistent threat of social engineering attacks, even against large, well-resourced organizations. While consumer data was protected in this instance, the compromise of corporate data can still lead to intellectual property theft, competitive disadvantages, or provide a foothold for future, more severe attacks. This incident serves as a reminder that all types of organizational data require stringent protection measures.

Actionable Recommendations for Defending Against Social Engineering

Organizations, particularly those with a large employee base, must prioritize defenses against sophisticated social engineering campaigns. The following recommendations are critical for mitigating corporate data exfiltration risks and enhancing overall security posture:

  • Comprehensive Employee Training: Implement ongoing, realistic training programs that teach employees how to identify and report phishing, vishing (voice phishing), and other social engineering attempts. Training should go beyond basic awareness and include simulated attacks to test employee vigilance.
  • Multi-Factor Authentication (MFA): Enforce MFA across all corporate systems and applications, especially for accessing sensitive data or remote resources. This adds a critical layer of security, making it significantly harder for attackers to leverage stolen credentials.
  • Endpoint Detection and Response (EDR): Deploy advanced EDR solutions to monitor endpoints for suspicious activity, detect potential compromises early, and enable rapid containment and remediation of threats.
  • Principle of Least Privilege: Ensure that employees only have access to the data and systems absolutely necessary for their job functions, thereby limiting the potential damage if an account is compromised.
  • Incident Response Plan Review: Regularly review and update incident response plans, focusing specifically on scenarios involving social engineering and data exfiltration, to ensure swift and effective action.
  • Continuous Monitoring: Maintain continuous monitoring of network traffic, user behavior, and system logs to proactively detect anomalies that could indicate an ongoing attack or data theft. Proactive measures are key to detecting social engineering attacks before they lead to significant breaches.

Related: BlackFile: Analyzing UNC6671 Vishing & Cloud Data Extortion, Anatomy of E-Commerce Fraud: Detecting and Mitigating Phishing Sites

Advertisement

Advertisement