Full Report
Crims talked their way onto three employee PCs before trousering corporate data
Analysis Summary
# Incident Report: Social Engineering Compromise of Levi Strauss & Co.
## Executive Summary
In August 2026, Levi Strauss & Co. identified a security breach resulting from a targeted social engineering campaign. Attackers successfully gained access to three employee workstations and exfiltrated corporate data; however, the company reports no impact on consumer data or operational continuity. The incident was contained by internal security teams and external experts, with no expected material impact on business finances.
## Incident Details
- **Discovery Date:** August 2026
- **Incident Date:** July – August 2026
- **Affected Organization:** Levi Strauss & Co.
- **Sector:** Retail / Manufacturing
- **Geography:** Global / United States
## Timeline of Events
### Initial Access
- **Date/Time:** Circa July/August 2026.
- **Vector:** Voice Phishing (Vishing) / Social Engineering.
- **Details:** Attackers contacted employees on personal mobile devices posing as IT support or colleagues to solicit credentials and MFA codes.
### Lateral Movement
- **Details:** After harvesting credentials via spoofed login pages, attackers gained access to three specific employee PCs.
### Data Exfiltration/Impact
- **Details:** Attackers successfully "trousered" (exfiltrated) certain corporate information. The specific nature of the data has not been disclosed, though preliminary findings suggest consumer data was not reached.
### Detection & Response
- **Discovery:** Levi's internal monitoring identified unauthorized access.
- **Response:** Activated incident response protocols, engaged third-party cybersecurity forensic experts, and terminated unauthorized access points.
## Attack Methodology
- **Initial Access:** Social Engineering (Vishing) and Credential Harvesting.
- **Persistence:** Access to physical/virtual employee workstations.
- **Defense Evasion:** Use of spoofed login pages to bypass Multi-Factor Authentication (MFA).
- **Credential Access:** Harvesting of usernames, passwords, and MFA tokens via "man-in-the-middle" or spoofing techniques.
- **Exfiltration:** Transfer of corporate files from compromised workstations to attacker-controlled infrastructure.
- **Impact:** Unauthorized data disclosure (Confidentiality breach).
## Impact Assessment
- **Financial:** No material impact expected per regulatory filings.
- **Data Breach:** Corporate information exfiltrated; consumer data remains unaffected.
- **Operational:** None; business operations continued without disruption.
- **Reputational:** Moderate; the incident highlights the ongoing vulnerability of employees to sophisticated social engineering.
## Indicators of Compromise
- **Network Indicators:** Spoofed login domains mimicking internal Levi’s or SSO portals (e.g., `levis-okta[.]com` - *example of defanged format*).
- **Behavioral Indicators:** Unexpected calls from "IT Support" to personal mobile numbers; requests for MFA codes over the phone.
## Response Actions
- **Containment:** Revocation of compromised credentials and disconnecting affected workstations.
- **Eradication:** Engagement of external experts to scan for backdoors and ensure the removal of attacker presence.
- **Recovery:** Restoration of secure access and notification of relevant regulatory bodies (SEC).
## Lessons Learned
- **Vulnerability of Personal Devices:** Attackers are increasingly bypassing corporate perimeters by targeting employees on personal mobile phones.
- **MFA is Not a Silver Bullet:** Traditional MFA can be bypassed through real-time social engineering where the attacker "proxies" the code provided by the victim.
- **Rapid Containment:** Early detection and the use of external experts prevented the lateral movement from reaching sensitive consumer databases.
## Recommendations
- **Transition to Phishing-Resistant MFA:** Implement hardware security keys (e.g., FIDO2/WebAuthn) to prevent the harvesting of MFA codes.
- **Security Awareness Training:** Conduct specific "Vishing" simulations to teach employees that IT support will never ask for MFA codes over the phone.
- **Data Minimization:** Ensure that sensitive corporate data is not unnecessarily stored on individual employee workstations to limit the "blast radius" of a local compromise.