
Levi Strauss & Co. has disclosed a cybersecurity incident in which an unauthorized third party used social engineering to gain access to three employees’ company-issued computers and steal corporate information.
The apparel company said in a Form 8-K filing with the US Securities and Exchange Commission (SEC) that it detected the intrusion recently and responded by activating its incident-response procedures, containing the unauthorized access, and bringing in third-party cybersecurity specialists to investigate.
According to preliminary findings, the attackers accessed and exfiltrated unspecified corporate information. Levi Strauss said it currently has no evidence that consumer information was affected and has experienced no disruption to its business operations.
The company also said it does not believe the breach has had, or is reasonably likely to have, a material effect on its business strategy, operations, financial condition, or financial results. Notifications are being provided to affected parties and regulators where required.
Levi Strauss, headquartered in San Francisco, is one of the world's largest apparel companies, best known for its Levi's denim brand.
The company did not disclose when the intrusion began, what social-engineering techniques were used, which systems or files were accessed, or any information about the attackers.
Reuters reported that internet intelligence and Google data showed infrastructure associated with ransom-seeking hackers had been created to target more than 200 companies during the previous five weeks, including Levi Strauss.
UNC6671 uses helpdesk calls to steal cloud data
The disclosure comes as the Google Threat Intelligence Group (GTIG) published new research on UNC6671, a financially motivated threat cluster that conducts data-theft extortion attacks through voice phishing.
According to Google researchers, UNC6671 callers impersonate corporate IT helpdesk personnel and contact employees, sometimes on their personal phones, with urgent requests involving security migrations, MFA enrollment, or FIDO2 passkeys. Victims are directed to convincing authentication portals controlled by the attackers.
These sites use adversary-in-the-middle infrastructure to capture credentials and MFA tokens. After obtaining a persistent authenticated session, the attackers can use scripts to extract information from cloud and SaaS environments such as Microsoft 365 and Okta.
Google says UNC6671, previously associated with the BlackFile extortion operation, appears connected through shared infrastructure and tactics to several newer brands, including Redact, Pink, Helix, and Falcon. Identical phishing templates and overlapping domains have been observed across victims later extorted under different names.
The group has also increasingly attempted to hide its activity by deleting password-reset emails, security notifications, and alerts generated when account or MFA settings are changed. Google observed its targeting accelerate during June and July, with campaigns increasingly focused on technology companies, financial firms, private equity, and legal organizations.







Leave a Reply