Social Engineering Scam Breaches Levi Strauss Company Files

Levis

Levi Strauss & Co. has disclosed that an unauthorized third party accessed company files through a social engineering scam, according to the company’s Friday (Aug. 7) filing with the Securities and Exchange Commission.

    Get the Full Story

    Complete the form to unlock this article and enjoy unlimited free access to all PYMNTS content — no additional logins required.

    yesSubscribe to our daily newsletter, PYMNTS Today.

    By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions.

    The jeans and apparel company said in the filing that it recently detected that it “experienced a cybersecurity incident in which an unauthorized third party gained access to Company files through social engineering techniques that enabled unauthorized access to three employees’ Company-issued computers.”

    Following its detection of the incident, Levi Strauss & Co. initiated response protocols, implemented containment measures, launched an investigation, engaged the services of third-party cybersecurity experts and notified affected parties and applicable regulators, according to the filing.

    Based on preliminary findings from its investigation, Levi Strauss & Co. believes some corporate information was accessed and exfiltrated during the incident. The company said it believes that it terminated the unauthorized access, that no consumer data was impacted, and that the incident is unlikely to have a material impact on its business.

    “The Company has not experienced any interruption in business operations as a result of the incident,” Levi Strauss & Co. said in the filing.

    The Federal Bureau of Investigation (FBI) said in an April2024 public service announcement that cyber criminals were targeting individuals and businesses with social engineering techniques.

    These techniques include impersonating employees to update employee login information and gain access to a company’s network; contacting a victim’s mobile carrier and convincing the carrier to transfer the victim’s mobile number to the cybercriminal’s device and then using that number to bypass multi-factor authentication; and posing as a trusted institution or as the employer’s VPN portal to solicit the victim’s information and login credentials, according to the announcement.

    Google Threat Intelligence Group (GTIG) said in a Thursday (Aug. 6) blog post that several threat actors are targeting enterprise employees through voice phishing (vishing), often via the employees’ personal mobile devices, and posing as IT helpdesk staff facilitating what they say are mandatory, urgent security migrations.

    The threat actors then lure victims to spoofed login portals, intercept the victims’ credentials and multi-factor authentication, and deploy automated scripts for data exfiltration from enterprise cloud environments.

    Verizon said in May that social engineering played a role in 16% of the 22,000 confirmed data breaches across 145 countries that it analyzed in a recent report.