
Levi Strauss & Co. disclosed Friday that hackers gained unauthorized access to corporate files after compromising three company-issued computers through a social engineering attack. The San Francisco-based denim maker — which operates nearly 3,300 stores worldwide and employs about 19,000 people — filed the breach notification with the U.S. Securities and Exchange Commission. The company said the attackers exfiltrated certain corporate information but did not specify what type of data was taken.
Levi Strauss said it contained the breach shortly after discovering it and that the incident did not disrupt business operations. Crucially, the company says there is no evidence that consumer data was affected. The attackers have not been identified, and no ransomware or ransom demand has been disclosed. No hacking group has claimed responsibility, and the investigation remains ongoing.
The disclosure adds Levi Strauss to a lengthening list of retailers hit by social engineering campaigns. British retailers Harrods, Marks & Spencer, and The Co-op faced cybersecurity incidents in 2025. Fast-fashion brand Mango and The North Face disclosed breaches last year. Dutch luxury department store De Bijenkorf reported a third-party cyber incident earlier this week. The FBI and other authorities have stepped up warnings to companies about the growing wave of criminal social engineering attacks targeting employees to gain initial access to corporate systems.
