In short: In early August 2026, attackers tricked three Levi Strauss employees over the phone, gained remote access to their work computers, and exfiltrated corporate files. No technical vulnerabilities were exploited — only persuasive voices and knowledge of corporate procedures. The incident is part of a wider vishing campaign that hit staff at more than 200 companies over five weeks.
What happened
On August 7, 2026, Levi Strauss & Co. filed notifications with the SEC and the California Department of Justice disclosing a cybersecurity incident. Attackers called several company employees, posed as colleagues or IT helpdesk staff, and persuaded them to surrender access to their work computers. From three compromised machines, they downloaded "certain corporate files" — the exact contents were not disclosed. Customer data was not affected. Store operations were not disrupted. For a look at how data can leak without a device being directly hacked, see our guide on voice deepfakes and social engineering scams.
Vishing: how the voice-based attack works
Vishing (voice phishing) is a form of social engineering carried out over a phone call rather than email. The scenario is familiar: "IT support" reports suspicious activity or an urgent system update, then asks the employee to install a remote access tool or navigate to a corporate login page. The employee complies — and the attacker gains control of the computer.
The Levi Strauss attack has been linked by researchers to UNC6671, a threat cluster tracked by Google. According to Reuters, over five weeks the group ensnared employees at more than 200 companies, including major US financial institutions. The same attack pattern — a call instead of a hack — also drives two-call one-time-password scams.
The defining feature of vishing: it bypasses every technical control. Antivirus, multi-factor authentication, strong passwords — none of it helps once the person willingly hands over access. This is why attacks on the human factor remain a priority vector for sophisticated threat groups.
What this means for ordinary users
Levi's confirmed that customer data is safe. But the incident highlights a familiar pattern: people remain the weakest link in any security system. The technical protections on your device are powerless once an attacker gains access through you — with your own consent, given under deception. For practical account protection steps, see our guide on protecting accounts from compromise.
How to protect yourself against vishing
- Don't trust unexpected calls. If "IT support" asks you to install software or transfer access — hang up and call back on an official number you find yourself, not one the caller provides.
- Never follow links dictated over a call. A "corporate login page" given over the phone may be a phishing copy. Always type URLs manually or use a saved bookmark.
- Minimise your public footprint. The less an attacker knows about your job title, manager, and internal processes, the harder it is to build a convincing cover story. Review your privacy settings on LinkedIn.
- Use a VPN on public and corporate networks. Social engineering isn't the only threat. LiMP VPN encrypts traffic and hides your IP address, protecting against data interception on unsecured networks — particularly relevant for remote workers connecting from cafés or co-working spaces.
