Attackers breach Levi's corporate network via social engineering
TL;DR. Levi Strauss is investigating a data breach after social engineering allowed attackers to access three employee computers. - Intruders exfiltrated unspecified corporate information, but no consumer data was compromised in the attack. - Google researchers track a wider campaign, UNC6671, which targets companies with similar social engineering tactics. - The attackers impersonate colleagues or IT support to harvest login credentials and multi-factor authentication codes.
- Levi's confirmed a data breach affecting three employee computers through social engineering.
- Corporate data was exfiltrated, but no customer data was compromised.
- The attack is part of a broader social engineering campaign tracked by Google researchers (UNC6671).
- Attackers use spoofed login pages and impersonation to steal credentials and MFA codes.
Sources
- Attackers pick Levi's pockets in social engineering attack — theregister.com