Levi Strauss & Co., the renowned clothing giant, has disclosed a cybersecurity incident in which hackers used social engineering to gain access to and steal corporate data stored on company-issued computers. The company, known for its signature 501-line jeans, operates at least 3,300 stores worldwide and has an annual revenue of $6.3 billion.
Cyberattack Details
The incident occurred when an unknown attacker social-engineered three of Levi Strauss & Co.'s employees, resulting in the breach of company-issued computers. The company has stated that its response was sufficiently quick to prevent the compromise of consumer data. According to a filing with the U.S. Securities and Exchange Commission (SEC), Levi Strauss & Co. believes that certain corporate information was accessed and exfiltrated as a result of the incident.
However, the company has confirmed that no consumer data was impacted, and it has not experienced any interruption in business operations as a result of the incident. The investigation launched in response to the incident remains ongoing, and additional notifications will be provided to affected parties as required.
Potential Threat Actor
Although Levi Strauss & Co. could not identify any threat actors claiming the attack, some media outlets have linked this incident to UNC6671, which Google's Threat Intelligence Group (GTIG) associated with a recent wave of voice phishing attacks targeting hundreds of organizations.
As a precaution, holders of Levi's shop accounts should monitor for suspicious activity and promptly report it to the firm. The company's rapid response efforts successfully contained and terminated the unauthorized access, and it does not believe the incident will have a material impact on its business or financial position.
Importance of Cybersecurity
The incident highlights the importance of cybersecurity and the need for companies to have robust security measures in place to prevent such attacks. According to a Picus whitepaper, security teams log 54% of successful attacks and alert on just 14%, with the rest moving through the environment unseen.
The whitepaper also shows how breach and attack simulation tests can help detect threats and prevent them from slipping by detection. As such, it is crucial for companies to test every layer of their security before attackers do.
In related news, a man was recently sentenced to six years for hacking 750 women's Snapchat accounts, and healthtech firm Xolis suffered a data breach impacting 1.4 million people. Additionally, Valve notified Steam hardware customers of a data breach, highlighting the need for companies to be vigilant in protecting their customers' data.
In conclusion, the cyberattack on Levi Strauss & Co. serves as a reminder of the importance of cybersecurity and the need for companies to have robust security measures in place to prevent such attacks. As the threat landscape continues to evolve, companies must remain vigilant in protecting their customers' data and preventing unauthorized access to their systems.
- Related Articles:
- Man gets six years for hacking 750 women's Snapchat accounts
- Webinar tomorrow: Why modern email attacks require a new approach to defense
- Healthtech firm Xolis suffers data breach impacting 1.4 million people
- Webinar: How behavioral AI stops phishing and account takeovers
- Valve notifies Steam hardware customers of a data breach
Source: BleepingComputer