Levi Strauss discloses cyberattack to SEC after corporate data stolen from employee computers

Levi Strauss discloses cyberattack to SEC after corporate data stolen from employee computers

Denim maker Levi Strauss & Co has disclosed a cyberattack that gave attackers access to corporate information stored on company-issued computers. The incident was officially reported in an 8-K form filed with the US Securities and Exchange Commission (SEC).

According to the filing, the attack resulted from social engineering and affected computers belonging to three employees. The company says its immediate response and containment actions forced the attackers out of the compromised systems. Preliminary findings from the investigation indicate that certain corporate data was accessed and exfiltrated.

Levi Strauss stated that no customer data appears to have been stolen. The investigation is ongoing, but the company says the incident has not caused any disruption to business operations. The company also said it does not believe the event has had, or is reasonably likely to have, a material impact on its business.

The official notice does not identify the attackers, mention any extortion demands, or specify the type of social engineering used. However, unconfirmed reports suggest the hacking group UNC6671, known for recent voice phishing (vishing) campaigns, may be involved. SecurityWeek has contacted Levi Strauss for additional details and will update this article if the company responds.

Tags: Security
Slate (Sl8) — the new social network. Post, grow your audience and earn — plus staking rewards that actually pay.
Invite codehXA6hX
Join Slate