Levi Strauss & Co. has reported a cybersecurity incident involving unauthorized access to three company-issued computers through social engineering techniques. According to a filing with the U.S. Securities and Exchange Commission, attackers compromised employee devices to reach company files, resulting in the exfiltration of certain corporate information. The San Francisco-based apparel company, known for its Levi's denim brand, detected the breach and immediately activated response protocols.
The attackers used social engineering methods to gain initial access to the employee computers, which then served as entry points to broader company files. Levi Strauss engaged third-party cybersecurity experts to assist with the investigation, which remains ongoing. Preliminary findings indicate that while corporate information was accessed and removed from the network, the company's rapid response successfully contained and terminated the unauthorized access.
The company emphasized in its SEC filing that no consumer data was impacted by the incident. Business operations have continued without interruption, and Levi Strauss does not expect the breach to materially affect its business strategy, operations, financial condition, or results. The company reported net revenues of $6.3 billion for 2025, representing a 4% increase over the previous fiscal year.
This incident adds to a series of cybersecurity events affecting major retailers in recent months. Spanish fashion retailer Mango confirmed a data breach in October 2025 involving an external marketing provider, while Dutch department store De Bijenkorf experienced disruptions in August 2026 through a logistics partner compromise. Victoria's Secret temporarily shut down its U.S. website in May 2025 following a security incident, and UK authorities arrested four suspects in July 2025 for attacks against Marks & Spencer, Co-op, and Harrods.
Levi Strauss stated it is providing notifications to affected parties and applicable regulators in accordance with legal requirements. The company continues to investigate the full scope of the compromised information while maintaining that current findings do not indicate significant business impact. Organizations should review their social engineering defenses and employee security awareness training, as this attack method continues to prove effective against corporate targets.
Source: https://thecyberexpress.com/levi-strauss-cyberattack/


