Sat 08 Aug 2026 / 15:15 ET
Kernel
Security 2 min read

Levi Strauss cyberattack exposed unspecified corporate information

Levi Strauss says an intruder accessed three employee computers and extracted corporate data, while preliminary findings show no consumer-data impact.

Dana Voss

By Dana Voss / Security Correspondent

Levi Strauss cyberattack exposed unspecified corporate information
img: The Record

Levi Strauss cyberattack disclosure: the apparel company said Aug. 7 that an unauthorized third party used social-engineering techniques to get into three company-issued employee computers, then accessed and extracted unspecified corporate information.

The company made the disclosure in a regulatory filing. It did not identify the types of corporate information involved, the person or group responsible, or the precise social-engineering method used. That leaves no basis to label the incident phishing, voice phishing, ransomware, or anything else with more specificity.

Levi Strauss said its preliminary findings showed no consumer data was affected. That distinction is the useful part for customers: the company has disclosed access to corporate information, not a confirmed exposure of shopper data.

What did Levi Strauss say about the cyberattack?

Levi Strauss said it detected the incident, started its response procedures, put containment measures in place and brought in outside cybersecurity specialists. The company said it had contained and ended the unauthorized access, though its investigation remains underway.

The company also said the incident did not interrupt its business operations. Based on the information available when it filed, Levi Strauss said it did not expect a material effect on its strategy, operations, financial condition or operating results.

Those are the company’s current assessments, not a completed forensic account. It has not publicly detailed what files were taken, whether any affected parties must be notified, or whether additional findings could change its account.

What remains undisclosed?

  • The specific categories of corporate information that were accessed and extracted.
  • The identity of the unauthorized third party.
  • The exact social-engineering technique used to reach the three employee computers.
  • Whether ransomware was involved or whether anyone sought a ransom.

Social engineering describes a technique directed at people to obtain or compromise organizational information or computer systems, according to the U.S. Cybersecurity and Infrastructure Security Agency. Levi Strauss did not disclose the precise social-engineering method used in this case.

The disclosure concerns a separate event from an earlier reported credential-stuffing incident involving Levi Strauss customer accounts. The company’s Aug. 7 filing concerns access to employee computers and certain corporate information, and should not be folded into that earlier customer-account incident.

This story draws on original reporting from The Record.

More Security/

view all ↗