Levi Strauss & Co. Data Breach Exposes Corporate Employee Data

Published: 7 August 2026 · Last Updated: 16 August 2026
Retail data breach illustration
Breach Discovery: August 2026Breach Notification: August 2026

Levi Strauss & Co. confirmed hackers used social engineering, or voice phishing, to trick three employees into granting access to their company computers, allowing attackers to steal corporate data before security teams contained the intrusion. This primarily affected internal business information rather than customer accounts, though impacted employees and any notified parties should watch for further phishing attempts and promptly follow Levi's official guidance on securing their accounts.

CompanyLevi Strauss & Co.
IndustryRetail
Data Types ExposedInternal Corporate Communications, Business Documents, Operational Data, Possible Employee Personal Information
People AffectedNot Publicly Disclosed
Attack MethodVoice Phishing
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Levi Strauss & Co. Data Breach?

Levi Strauss & Co., the denim and apparel company known worldwide for its jeans, has confirmed a cybersecurity incident involving stolen corporate data. The company disclosed the breach in a filing with the U.S. Securities and Exchange Commission. According to that filing, hackers used social engineering tactics to trick three employees into granting access to their company-issued computers.

As a result of this access, attackers accessed and removed certain corporate information from the compromised machines. The exact timeline of when the intrusion began has not been publicly disclosed beyond the recent filing. However, Levi’s says its security team detected the activity and moved quickly to contain it.

Because the company responded rapidly, it believes the unauthorized access was successfully shut down before it could spread further. The investigation into the incident is still ongoing. Levi’s has said that additional notifications will go out to affected parties as the investigation continues and as required by law.

Some security researchers and media outlets have connected this attack to a group known as UNC6671. This group has reportedly been linked to a broader wave of voice phishing attacks targeting numerous organizations. No threat actor group has publicly claimed responsibility for the Levi’s incident specifically, so this connection remains unconfirmed.

Who was affected?

Based on the information Levi’s has released, this breach primarily affected the company’s internal corporate data rather than customer accounts. The three employees whose computers were compromised likely had access to sensitive business files, communications, or internal systems. The exact number of individuals or records affected by this breach has not been publicly disclosed.

Levi’s has stated that it does not believe consumer data was compromised in this incident. This distinction matters because it suggests the exposure is currently limited to internal corporate information rather than the personal data of the company’s millions of customers. Still, until the investigation concludes, the full scope of affected individuals, including any employees whose personal information may have been on those machines, remains unclear.

What Information Was Potentially Exposed?

Levi’s has not released a detailed breakdown of exactly what corporate information was taken. However, based on the nature of the attack and the type of data typically stored on employee work computers, several categories of information could be at risk. The company has indicated the investigation is ongoing, so more specifics may come to light later.

  • Internal corporate communications and documents
  • Business files stored on compromised employee computers
  • Potentially sensitive company operational data
  • Possible employee personal information, if stored on the affected machines

Even when a breach is described as limited to corporate data, there is still meaningful risk. For example, internal emails and documents can contain details about employees, vendors, or business partners that could be misused. If any personal information about staff was stored on those machines, those individuals could face a heightened risk of phishing or identity theft attempts.

In addition, stolen corporate data is sometimes used by attackers for further social engineering. This means employees, vendors, or even customers could see follow-up phishing attempts that reference real internal details to appear more convincing. As a result, vigilance remains important even though Levi’s says consumer data was not affected.

What is the company doing?

Levi’s says it responded quickly once it detected the unauthorized activity. The company states that its rapid response efforts contained and terminated the unauthorized access. Because of this swift action, Levi’s believes the incident did not disrupt its business operations or affect its financial position in a material way.

The investigation into the incident remains active. Levi’s has committed to providing additional notifications to affected parties as more information becomes available and as legally required. The company has also encouraged holders of Levi’s shopping accounts to monitor their accounts for suspicious activity, even though it says consumer data was not impacted.

What Should Affected Individuals Do?

Monitor Your Accounts Closely

Anyone with a Levi’s shopping account should check their account activity regularly in the weeks ahead. Look for unfamiliar logins, changed account details, or unexpected orders placed under your name.

Because attackers linked to this type of incident sometimes attempt follow-up attacks, staying alert now can help you catch problems early. If you notice anything unusual, report it to Levi’s customer service right away.

Watch for Phishing and Social Engineering Attempts

Since this breach began with social engineering against employees, it’s worth remembering that similar tactics could be used against customers or partners too. Be cautious of unexpected emails, calls, or texts claiming to be from Levi’s, especially those asking you to verify account details or click a link.

Instead of clicking links in unsolicited messages, go directly to the official Levi’s website or app to check your account. This simple habit can prevent you from accidentally handing over credentials to a scammer impersonating the company.

Check Your Credit Reports Regularly

Even though Levi’s says consumer data was not affected, it is still wise to periodically review your credit reports for any signs of unfamiliar activity. You can request free credit reports from the three major credit bureaus once a year, or more frequently in some cases.

This is a good general practice regardless of any specific breach, but it becomes especially relevant whenever a company you do business with reports any kind of security incident. Catching unauthorized accounts or inquiries early can limit potential damage.

Stay Informed as the Investigation Continues

Because Levi’s investigation is still ongoing, more details could emerge about what data was actually taken and who was affected. Keep an eye on official company communications and any notifications you may receive directly from Levi’s.

If you later learn that your personal information was part of this breach, consider speaking with a data breach attorney. An attorney can help you understand your rights and whether you may be eligible for compensation.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

View the public data breach notification listing from Oregon Department of Justice

Related Data Breaches

Browse all recent data breaches →