№219|03:15 PM ET
Independent reporting on technology, markets & policy
TechEchelon
№01 / Anchor·CYBERSECURITY

Levi Strauss Says Hackers Stole Corporate Data After Social Engineering Three Employees

Levi Strauss & Co. disclosed in an SEC filing that hackers used social engineering to compromise three employees' computers and steal corporate data, though the company said no consumer data was affected.

TE
TechEchelon Staff
AUG 7, 2026 · 01:01 PM ET · 2 MIN READ
via Wikipedia (Levi Strauss & Co.)

Levi Strauss & Co. disclosed Thursday that hackers used social engineering tactics against three of its employees to gain access to corporate data stored on company-issued computers, according to a filing with the U.S. Securities and Exchange Commission.

The apparel company, known for its 501-line jeans and operating more than 3,300 stores worldwide, said its investigation found that certain corporate information was accessed and removed from its systems. The breach did not affect consumer data, the company said.

"Based on preliminary findings from the Company's investigation, the Company believes that certain corporate information was accessed and exfiltrated as a result of the incident," Levi's said in its SEC filing. "As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, and that no consumer data was impacted."

The company, which employs roughly 19,000 people and reported annual revenue of $6.3 billion, added that it has not experienced any interruption in business operations as a result of the incident.

The breach, first reported by BleepingComputer, involved an unknown attacker who socially engineered three Levi's employees, ultimately compromising their company-issued machines. The specific nature of the corporate data taken has not been disclosed.

Levi's said its internal investigation remains ongoing and that it will provide additional notifications to affected parties as required. Based on findings to date, the company said it does not believe the incident will have a material impact on its business or financial position.

Some outlets have linked the attack to a threat actor tracked as UNC6671, a group that Google's Threat Intelligence Group has associated with a recent wave of voice phishing attacks targeting hundreds of organizations. Levi's has not publicly confirmed any attribution, and no threat actors had claimed responsibility for the breach as of the time of publication.

The incident underscores the continuing effectiveness of social engineering as an entry point for corporate intrusions — a method that bypasses technical defenses by targeting employees directly. Voice phishing, also known as vishing, has emerged as a particularly active vector in 2026, with the UNC6671 cluster linked to a broad campaign across multiple industries.

The retailer's products are sold through its own storefronts as well as third-party retail channels both in physical locations and online, giving the breach potential significance for business partners even if direct consumer account data was not among the exfiltrated material.

With the investigation still in its early stages, the full scope of what was taken — and by whom — remains unclear. Levi's has said further disclosures will follow as required by applicable notification obligations.

Disclaimer

TE
━ ABOUT THE BYLINE
TechEchelon Staff

TechEchelon Staff bylines are produced collectively by the newsroom for short, breaking, and wire-style coverage. Longer-form reporting is published under the responsible reporter's name.

More from the Staff
● THE BRIEF · DAILY NEWSLETTER

Five stories every morning. Before the opening bell.

Written for readers who already know the basics — markets, AI, and the policy decisions that shape both.

Mon — Fri · 06:30 ET · Free

No spam · Unsubscribe anytime