Cybersecurity

Social Engineering Breach Impacts Levi Strauss & Co. Corporate Data

FORTSECURE GLOBAL· 2026-08-10🛰 The Register - Security
#Social Engineering#Data Breach#Corporate Security#Phishing
Social Engineering Breach Impacts Levi Strauss & Co. Corporate Data

A recent social engineering attack allowed cybercriminals to infiltrate Levi Strauss & Co. employee systems, resulting in unauthorized access to corporate data.

The iconic apparel brand Levi Strauss & Co. recently fell victim to a targeted social engineering campaign that allowed attackers to gain unauthorized access to several corporate systems. According to recent reports, the attackers successfully manipulated three separate employees into providing access to their workstations, effectively 'picking the pockets' of one of the world's most recognizable retailers. This incident underscores a critical reality in modern cybersecurity: the human element remains the most vulnerable point in the security perimeter. ## The Mechanics of the Attack. Social engineering is a tactic that relies on psychological manipulation rather than technical exploits. In this specific incident, the criminals used persuasive communication techniques—likely via phone calls (vishing) or messaging—to convince employees to grant them remote access to their devices. Once the attackers secured access to these three PCs, they were able to pivot into the corporate network and exfiltrate sensitive data. This 'low-tech' approach bypassed sophisticated firewalls and endpoint protection because the employees themselves essentially 'opened the door' for the intruders. The psychological pressure applied by these criminals often involves creating a sense of urgency or mimicking the authority of IT support staff, making it difficult for even well-meaning employees to detect the fraud in the moment. ## Mitigation and Best Practices. To combat the rising tide of social engineering, FORTSECURE GLOBAL recommends a comprehensive defense-in-depth strategy. First, organizations must move beyond generic security training and implement interactive, scenario-based simulations that teach employees how to identify and report suspicious requests. Second, the implementation of Phishing-Resistant Multi-Factor Authentication (MFA), such as hardware-based security keys, is essential to prevent account takeover even if an employee is compromised. Third, companies should adopt a Zero Trust security model where no user or device is trusted by default. This includes strict identity verification and limiting the 'blast radius' of a breach by segmenting the network. Finally, establishing a 'no-blame' reporting culture ensures that employees feel comfortable reporting a mistake immediately, which can drastically reduce the time it takes for incident response teams to contain an ongoing attack.


แหล่งที่มา: The Register - Security เผยแพร่ครั้งแรก: Mon, 10 Aug 2026 15:36:00 +0200 บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: The Register - Security

เผยแพร่ครั้งแรก: Mon, 10 Aug 2026 15:36:00 +0200

บทความต้นฉบับ: https://www.theregister.com/security/2026/08/10/attackers-pick-levis-pockets-in-social-engineering-attack/5285401

อ่านบทความต้นฉบับ ↗

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog