The recent cyberattack suffered by Levi Strauss & Co. once again brings one of the biggest challenges of corporate cybersecurity to the forefront: criminals do not always need to find an advanced vulnerability to get into a company. In this case, an unauthorized third party managed to gain access to corporate systems after using social engineering techniques against three company employees. The U.S. company reported the incident on August 7, 2026, and explained that, although certain corporate information was accessed and extracted, its business operations were not disrupted and it did not expect a material impact on its results.
The incident becomes even more significant because it is not an isolated attack within the current landscape of digital threats. Available information points to a broader campaign in which cybercriminals have used phone calls, impersonation, and other manipulation techniques to attempt to gain access to numerous organizations. Data analyzed during the previous weeks showed that more than 200 companies had been prepared as potential targets in a campaign of this type, demonstrating that social engineering-based attacks can be carried out on a considerable scale. The Levi Strauss case thus serves as an example of a trend affecting companies across very different sectors and forcing a reconsideration of how cybersecurity is understood.
A Cyberattack That Started with People, Not a Machine
Social engineering is one of the oldest techniques used by cybercriminals, but in recent years it has acquired extraordinary importance within the cyberattack landscape. Instead of attempting to directly exploit a computer system, the attacker seeks to manipulate a person into providing information, allowing access, or carrying out an action that facilitates the cyberattack. This strategy can rely on email, instant messages, social networks, or phone calls, and normally attempts to exploit human factors such as trust, urgency, fear, or authority to carry out a cyberattack with greater chances of success.
In the case of Levi Strauss, the company stated that three employees were targeted in a social engineering operation that allowed an unauthorized third party to access its systems. The company has not publicly explained all the details regarding the specific way in which the deception occurred, so it is not possible to state with certainty whether a phone call, an email, a fake webpage, or another cyberattack mechanism was used. What is confirmed is that the human factor was used as an entry point and that, subsequently, the attackers managed to access and extract certain corporate information, demonstrating how a cyberattack can begin without directly exploiting a technological vulnerability.

This point is especially relevant because it demonstrates that even organizations with significant investments in security continue to depend on the decisions made by their employees when facing a potential cyberattack. A company may have advanced detection systems, multifactor authentication, device protection, and access controls, but an attacker who manages to impersonate a legitimate person can find an alternative way to carry out a cyberattack. The question is no longer only how to protect a network against an intruder, but also how to prevent someone from convincing an employee that the intruder is an authorized person, especially when that manipulation can become the first step of a larger-scale cyberattack.
The Real Danger Begins After Gaining Access
For cybercriminals, obtaining an account or entering a corporate computer rarely represents the ultimate objective of a cyberattack. The initial access can be used to explore a company’s technological environment, identify other users, locate information of interest, and determine which systems can be reached from the compromised device. The greater the level of permissions of the affected account, the greater the possibilities of expanding a cyberattack and turning an initial intrusion into a larger-scale problem.
The information disclosed by Levi Strauss indicates that the attackers accessed certain systems and extracted corporate information during the cyberattack. The company activated its response protocols, implemented containment measures, and launched an investigation to determine the scope of the incident. So far, the company has indicated that the cyberattack did not disrupt its operations and that it does not expect it to have a material impact on the business, although the investigation remains an important element in determining exactly how the access occurred and what consequences it may have had.
The difference between accessing and extracting information is also fundamental to understanding the severity of a cyberattack. An account may have been compromised without necessarily having all the documents available to that user stolen, but investigators need to review logs and systems to determine what activity the attackers carried out during the cyberattack. This task can take time, especially when the organization has thousands of employees, numerous cloud services, external providers, and systems connected to each other, as all these elements can expand the potential attack surface of a cyberattack.
Corporate Information Is Also a High-Value Target
When talking about cyberattacks, much of the attention usually focuses on consumers’ personal data. However, a company’s internal information can be extremely valuable to an attacker and become one of the main targets of a cyberattack, even when it does not contain card numbers, passwords, or medical data. Contracts, financial documents, business strategies, information about suppliers, internal communications, product plans, and other files can become valuable assets for those seeking to obtain money or prepare new cyberattacks.
A global company such as Levi Strauss handles large amounts of information related to its international operations. The company has relationships with manufacturers, suppliers, distributors, employees, business partners, and technology platforms, so its corporate environment is necessarily complex and can offer different opportunities for a cyberattack. An attacker who obtains internal information can use it not only to extort the organization, but also to build more convincing cyberattacks against other people connected to it.
For this reason, a data breach does not necessarily have a visible effect on the same day that a cyberattack occurs. A stolen document may appear months later in a fraud campaign, an internal conversation may provide information to impersonate an executive, and a contact list may be used to prepare new cyberattacks against suppliers or employees. Corporate information can function as one piece within a chain of operations that continues long after the company has technically closed the initial breach, causing the consequences of a cyberattack to extend beyond the moment it was detected.
Levi Strauss Is Part of a Broader Wave of Attacks
The case of the U.S. fashion company occurred in an especially concerning context for businesses, marked by increasing cyberattack activity targeting organizations across different sectors. Investigations cited in recent days have identified activity against numerous U.S. organizations, including financial institutions, investment firms, companies, and professional services firms. The campaign has used social engineering methods and phone calls to attempt to convince employees to provide credentials or allow certain actions that can facilitate a cyberattack.
One of the most striking elements is the number of organizations that can be prepared as targets within a cyberattack campaign. Data analyzed by researchers pointed to more than 200 companies that had been subject to digital preparation over approximately five weeks, suggesting an organized, coordinated, and scalable attack model. This changes the traditional perception of cybercrime, because it is no longer necessarily a matter of a criminal manually selecting a company and developing a specific cyberattack against it over the course of months.
The scale allows attackers to take advantage of economies similar to those of a legitimate business activity in order to multiply their cyberattacks. They can develop scripts, fake identities, fraudulent websites, technical infrastructure, and procedures that they then use against different organizations. If a portion of the victims falls into the trap, the effort can prove profitable even if other companies manage to detect the attempt and block the cyberattack before it compromises their systems.

Phone Calls Regain Prominence
For years, email phishing became one of the best-known methods for distributing fake links and stealing passwords, but recent cyberattacks demonstrate that the telephone remains an extraordinarily effective tool. A call allows the attacker to immediately respond to the employee’s questions, create a sense of urgency, and adapt the conversation according to the responses they receive. This ability to modify the cyberattack in real time can make the manipulation more convincing than a fraudulent message sent on a mass scale.
A method known as "vishing" uses voice calls precisely to carry out social engineering operations and facilitate a cyberattack. The attacker may present themselves as a technician from the IT department, a security officer, a coworker, or anyone else who has an apparently legitimate reason for requesting information. The conversation may even incorporate real information about the company to increase the credibility of the deception and ensure that the victim does not immediately identify the cyberattack.
The problem is that a phone call fits perfectly into a company's normal activities. Employees receive calls every day from colleagues, customers, suppliers, and internal departments, so an unexpected request does not always seem suspicious or get interpreted as part of a potential cyberattack. If, in addition, the person calling knows the employee’s name, their position, or the company’s structure, the deception can become even more convincing and increase the chances that the cyberattack will progress.
Impersonation of the IT Department Is Particularly Dangerous
IT departments have a natural advantage when they try to communicate with employees: they need to make requests that may seem extraordinary and that are part of a company’s routine tasks. An employee may receive a request to update a password, verify an account, install a tool, solve an authentication problem, or confirm a device. Many of these actions are perfectly normal within a modern company, which allows a cyberattack based on impersonating technical staff to go unnoticed.
Precisely for this reason, criminals may attempt to impersonate technical support personnel during a cyberattack. The person receiving the call may think they are cooperating to solve a problem rather than opening a door to an attacker. Once certain credentials or codes have been obtained, the criminal may attempt to use them to access corporate services and expand the scope of the cyberattack within the organization.
Campaigns of this type can also take advantage of legitimate authentication systems to make a cyberattack appear to be normal activity. If the attacker manages to get an employee to approve an access request that the attacker themselves generated, the action may initially appear to be authorized activity. This is why it is important to combine multifactor authentication with mechanisms capable of evaluating the context of each login, identifying anomalous behavior, and stopping a cyberattack before the access obtained can be used to compromise other systems.
Multifactor Authentication Is No Longer Enough on Its Own
Multifactor authentication has become one of the fundamental measures for protecting business accounts against a potential cyberattack. The principle consists of requiring more than one element to verify the user’s identity, reducing the risk that a stolen password will be enough to access a system and execute a cyberattack. However, attackers have developed methods designed to deceive people during that second authentication step as well.
An employee may receive an authentication request that was actually initiated by an attacker and approve it believing that it is a legitimate operation, thereby facilitating a cyberattack. They may also provide a one-time code during a fraudulent call or enter it on a page that imitates a corporate service and is part of the infrastructure used to execute the attack. The existence of a second factor improves security, but it does not eliminate the risk when the user themselves is manipulated during a cyberattack.
For this reason, organizations need to move toward systems that reduce the possibility of users being deceived into approving fraudulent access and that allow a cyberattack to be detected even when apparently valid credentials are being used. Phishing-resistant methods, controls based on trusted devices, contextual session evaluation, and conditional access policies can provide additional layers of protection against a cyberattack. The fundamental issue is that identity must be continuously verified and not only at the moment a password is entered, since legitimate access can subsequently become the entry point for a cyberattack.
Segmentation Can Limit the Damage
One of the most important lessons from social engineering attacks and cybersecurity incidents is that an organization must prepare for the moment when an account is compromised during a cyberattack. An effective strategy is to limit what each user and each device can do within the network, making it more difficult for an attacker to expand the scope of the cyberattack. If an employee only needs access to certain applications, they should not automatically have permission to access all corporate systems.
This principle, known as least privilege, can considerably reduce the impact of a cyberattack and limit an attacker’s ability to move laterally. If an account is used by a cybercriminal, their ability to move through the organization will be more limited if systems are separated and permissions are carefully defined. Segmentation can also prevent a localized incident from quickly becoming a widespread cyberattack capable of affecting multiple areas of an organization.
The same reasoning can be applied to corporate devices and to monitoring their activity in order to detect signs of a potential cyberattack. A company must be able to identify which devices are connected, what activity they perform, and which applications they run, especially when there is a suspicion of a cyberattack. When a computer begins to behave differently from its usual pattern, that anomaly can become an alert signal that makes it possible to intervene before the attacker can advance, compromise other systems, or carry out a significant extraction of information.

The Levi Strauss case demonstrates that corporate cybersecurity is entering a stage in which the boundaries between traditional fraud and cyberattacks are becoming increasingly blurred. A phone call can be the beginning of a digital intrusion, a conversation can end up compromising a corporate account, and a person can become the entry point into an entire technological infrastructure. Attackers are taking advantage of this connection between human behavior and digital systems to develop cyberattacks that are increasingly scalable, personalized, and difficult to identify.
The company managed to contain the incident and has indicated that its operations were not interrupted and that it does not expect a material impact on its results. However, the extraction of corporate information and the fact that three employees were used as an entry point show that even global companies remain exposed to relatively simple techniques when these are combined with good preparation and effective manipulation. The cyberattack also demonstrates that having advanced technological systems does not completely eliminate risk, since cybercriminals may attempt to take advantage of human behavior to overcome certain security barriers.
Beyond Levi Strauss, the main warning affects all organizations that depend on digital systems. Protecting a company against a cyberattack no longer consists solely of building barriers around its servers, but also of protecting identities, verifying requests, limiting privileges, monitoring behavior, and preparing the entire organization to respond when a defense fails. In a landscape where hundreds of companies can simultaneously become targets, the cybersecurity strategy must assume that attackers will attempt to enter through whichever path proves easiest.
And that path will not always be a computer vulnerability. Sometimes it will be an apparently routine phone call, an urgent request for technical support, or a carefully prepared conversation designed to facilitate a cyberattack. The Levi Strauss experience demonstrates that the human factor remains one of the most contested areas of modern cybersecurity and that companies seeking to reduce their risks will have to protect both their systems and the people who use them.
Therefore, having a comprehensive prevention, detection, and response strategy is essential to reduce exposure to a cyberattack and limit its consequences. ITD Consulting can help organizations strengthen their technological infrastructure, improve their security controls, identify risks, and develop protection strategies adapted to the needs of each company. If you want to assess your organization’s security level, prevent potential cyberattacks, and have the support of technology and IT specialists, you can contact ITD Consulting by writing to [email protected].