Levi Strauss Hit by Social Engineering Attack, Corporate Data Walked Out the Door
Levi Strauss has filed an 8-K with the SEC disclosing a cyberattack that compromised corporate data held on company-issued machines belonging to three employees. The filing, made Friday, confirms the attackers got in through social engineering rather than some exotic technical exploit.
The company says it moved quickly to contain the breach and has since evicted the attackers from the affected systems. Whether that happened before or after the damage was done is a different question. Preliminary findings indicate that corporate data was both accessed and exfiltrated, though Levi Strauss was careful to note that customer data does not appear to have been taken.
Business operations, the company insists, were not disrupted. It also filed the standard corporate disclaimer that the incident is not expected to have a material financial impact. Make of that what you will.
What Levi Strauss has not disclosed: who carried out the attack, what kind of social engineering was used, or whether anyone has demanded money. Unconfirmed reports point toward UNC6671, a threat group linked to a string of recent voice phishing operations, though the company has neither confirmed nor denied any involvement.
The investigation is ongoing. Given the vague disclosures so far, it would be surprising if the full picture looked as tidy as the 8-K implies.