Hackers talked their way into Levi’s, and three computers were enough

There was no exploit and no malware. Someone rang three employees, and that was enough to get corporate data out of the door.


Hackers talked their way into Levi’s, and three computers were enough
Image Credits Credit: Canva

Levi Strauss has disclosed a breach that involved no software vulnerability at all. Attackers used social engineering to reach three employees’ work computers, then took corporate data out with them.

The company set out the incident in a regulatory filing with the SEC on 7 August. Intruders accessed and exfiltrated “certain corporate information”, the filing says, and it does not say what that information was.

The Register’s Carly Page reported the disclosure on Monday. Levi’s spotted the intrusion, started incident response, brought in outside cybersecurity experts and cut off the access.

What the filing says, and what it leaves out

The disclosure runs to a few short paragraphs under Item 8.01, the heading a company uses for events no other item covers. David Jedrzejek, the general counsel, signed it.

The reassurances are precise. A preliminary investigation found no consumer data involved. Operations never stopped. The company does not believe the incident is reasonably likely to have a material impact on its business or its results.

The silences are just as precise. Levi’s has not said what the intruders took, or who it thinks they were. It has not said whether anyone demanded money, the step that turns a theft into a data extortion case.

A campaign, not a one-off

Reuters reported that Levi’s sits inside a much larger wave. More than 200 companies have been targeted over the past five weeks by crews that seek ransoms and rely on conversation rather than code.

Google researchers are tracking several of those crews under an umbrella they call UNC6671. The method is consistent: phone an employee on a personal mobile, pose as a colleague or as IT support, then steer the target to a spoofed login page.

That page harvests the password and the one-time code together. It is why multi-factor authentication stops being a barrier here, and becomes one more thing to read out loud.

Google gives these clusters numbers rather than names until it can attribute them. It tracked UNC5792 the same way, in the campaign that tricked people into linking their Signal accounts to a stranger’s device.

The targets move around. Google says these crews have previously gone after manufacturing, healthcare, insurance, technology and hospitality. Financial and legal firms have featured in the recent run.

Nobody has attributed the Levi’s breach

The link to UNC6671 is not established. The Register says plainly that there is no confirmation the group was behind this intrusion, and no threat actor has publicly claimed it.

Levi’s has named nobody either. A filing that avoids attribution while an investigation continues is normal practice, and it is also the reason the campaign framing should stay a framing rather than a finding.

Consumer brands have had a difficult year of this. Attackers reached Estée Lauder through an Oracle business system and walked off with corporate data.

Others fared worse. A ransomware attack on Coca-Cola’s Fairlife suspended US production, while Levi’s says its own operations carried on throughout.

The gap between those two outcomes is thinner than it looks. Levi’s caught this one early, and the same voice on the phone reaches a production line as easily as a laptop. What the company still has not said is how much left with it.

Get the TNW newsletter

Get the most important tech news in your inbox each week.