Businesses can experience cyberattacks at any time, even big-name corporations. Major firms around the world are experiencing an uptick in cyberattacks, including ransomware incidents that can disrupt operations or expose sensitive data.
That was the case for Levi Strauss & Co. The denim company recently disclosed that it had been the victim of a cyberattack that enabled an unauthorized third party to access its corporate information. Learn more about this security incident and its implications below.
What Happened?
Levi's recently filed a Form 8-K with the US Securities and Exchange Commission, disclosing the attack. According to the company's preliminary investigation, the hackers accessed and stole certain corporate information. Based on initial findings, it appears as though the hackers didn't steal customer data. The investigation is ongoing.
Who's Responsible for the Cybersecurity Breach?
Unfortunately, the preliminary investigation into the Levi's security incident has yet to name a responsible threat actor or group. The company has not disclosed whether it has received extortion demands, nor has it provided details about the type of social engineering the hacker used.
So far, no threat actors have claimed responsibility for the attack on the dark web. However, some publications are suggesting that UNC6671 may be involved. This particular group reportedly carries out data-theft extortion attacks via voice phishing.
So, how does it work? The group usually targets employees who can access a company's SaaS solutions. Someone posing as an IT worker would then try to persuade the employee to grant remote access or enter their login details on a malicious website.
There is no confirmation that UNC6671 is responsible. Specific details about the attack method have also not been disclosed.
What Businesses Can Do To Protect Consumer and Corporate Data
Levi Strauss has not revealed how the attackers deceived the three employees. Still, the incident shows why businesses need to prepare workers for suspicious calls, emails, and login requests. Here are a few steps businesses can take to safeguard sensitive information:
- Train employees to question unexpected requests: Employees should be cautious when someone asks for a login code or remote access to a company computer, even if the request seems urgent.
- Limit access to company data: Employees should only have access to the files and systems they need for their jobs.
- Make suspicious activity easy to report: Employees should know whom to contact if they click a questionable link, share information, or notice an unfamiliar login. Quick reporting gives the business a better chance to disable an account or isolate a device before the attacker goes further into the system.
The Levi's security incident is just the latest example of how sophisticated hackers are targeting major firms. Although the denim brand hasn't named the responsible party or disclosed what information the cybercriminals accessed, its quick containment of the threat may have helped prevent the hackers from obtaining additional corporate data.


