DATANEWS

Levi Strauss Confirms Data Exfiltration After Social-Engineering Cyberattack

Reuters · 2026-08-07

Levi Strauss disclosed that attackers used social engineering to gain unauthorized access to three employees’ company-issued computers and exfiltrate corporate information. The company said the incident was contained, consumer data was not affected and operations were not disrupted.

Why it matters: The incident converts a broader phishing campaign into a confirmed public-company compromise and highlights the continuing weakness of human identity-verification workflows.

Levi Strauss has disclosed a cybersecurity incident in which attackers used social-engineering techniques to gain access to three employees’ company-issued computers and extract corporate information.

The company said in an August 7 filing with the U.S. Securities and Exchange Commission that it detected unauthorized access, activated its incident-response procedures and brought in external cybersecurity specialists.

Preliminary findings indicate that certain corporate information was accessed and exfiltrated.

Levi said it has contained and terminated the unauthorized access, found no evidence that consumer data was affected and experienced no disruption to business operations. The company currently does not expect the incident to materially affect its financial condition or results.

The disclosure comes amid a broader wave of social-engineering attacks targeting U.S. businesses. Google threat-intelligence data reviewed by Reuters showed attackers creating customized phishing infrastructure for more than 200 companies, often using phone calls that impersonate corporate IT staff and pressure employees into resetting authentication credentials.

The Levi incident demonstrates that even organizations with substantial security controls remain vulnerable when attackers successfully compromise the human identity-verification layer.

Source and attribution →