Levi Strauss & Co has revealed that it recently experienced a cyberattack compromising some of its corporate data. The global denim company disclosed the incident on Friday, noting that the breach involved information stored on computers issued to certain employees.
Details of the Cyberattack
The company detailed the incident in a filing with the US Securities and Exchange Commission (SEC), highlighting that it resulted from social engineering tactics. Specifically, the attack targeted three employees’ computers, leading to unauthorized access to corporate information.
In response to the breach, Levi Strauss implemented rapid containment measures. The company successfully removed the attackers from the affected systems, ensuring no further unauthorized access occurred.
Impact and Current Investigation
Levi Strauss has communicated that their preliminary investigation suggests some corporate data was accessed and extracted during the breach. However, the company has not found any evidence indicating that customer data was compromised.
Despite the breach, the company has confirmed that its business operations have not been disrupted. Levi Strauss does not expect the incident to have any significant or lasting financial impact on the company.
Ongoing Investigation and Speculation
Currently, Levi Strauss has refrained from disclosing the identity of the perpetrators or if any ransom requests were made. The attack’s specifics, including the social engineering methods used, remain undisclosed.
Unconfirmed reports suggest that a hacking group known as UNC6671, notorious for voice phishing campaigns, might be linked to the attack. SecurityWeek has reached out to Levi Strauss for further information, pending a response from the company.
Related articles explore similar cybersecurity incidents, including a major data breach impacting Unlimited Technology Systems and a supply chain attack affecting over 400 NPM packages.
