Hackers Used Social Engineering to Steal Corporate Data from Levi Strauss & Co.
What Happened — Attackers leveraged a classic social‑engineering campaign against three Levi’s employees, gaining access to their company‑issued laptops and exfiltrating internal corporate files. The breach was disclosed in an SEC filing; the company says consumer data was not compromised and operations remain uninterrupted.
Why It Matters for Compliance & Audit Readiness
- This incident is a textbook example of a SOC 2 CC6 (Logical Access) failure: credentials were obtained without sufficient verification, highlighting gaps in access‑control policies and employee awareness.
- Continuous‑compliance programs must capture evidence that access controls (MFA, least‑privilege) are enforced and that security‑awareness training is regularly measured and updated.
- Verisq’s Security Awareness Training capability provides audit‑ready training records and post‑training assessments that map directly to SOC 2 access‑control criteria.
Who Is Affected — Retail & apparel sector; large consumer‑facing enterprises with distributed workforces.
Recommended Actions
- Verify that all privileged and standard accounts are protected by MFA and that least‑privilege principles are enforced.
- Conduct a rapid security‑awareness refresher focused on phishing and social‑engineering detection for all staff.
- Update your SOC 2 access‑control evidence repository with training completion logs and MFA enforcement reports.
- Review and tighten endpoint‑monitoring rules to detect anomalous file‑access patterns.
Source: BleepingComputer
Technical Notes — Attack vector: targeted phishing/social engineering → compromised laptops. No specific CVE; data exfiltrated includes internal corporate documents. No consumer PII reported. Source: same article