Iconic US denim brand Levi Strauss & Co — whose most famous marketing slogan was "There's stitching… and there's Levi's stitching" — has become the latest major corporation to fall victim to a socially-engineered cyber-attack. Hackers gained access to the computers of three employees, prompting the San Francisco-based company to file a disclosure with the US Securities and Exchange Commission (SEC).
In that filing, Levi's confirmed that, based on preliminary findings, certain corporate information was accessed and exfiltrated as a result of the breach. The company says no confidential customer information was stolen, and that it has implemented response protocols and containment measures intended to prevent wider access to its systems. The full extent of the breach has not yet been disclosed.
The scale of the target is significant. Levi Strauss operates nearly 3,300 retail stores worldwide, employs approximately 19,000 people, and generated $6.3 billion in net revenue last year, with a market capitalisation of over $9 billion. Yet even a company of that size and resource could not fully protect itself against a socially-engineered attack.
What is a socially-engineered attack?
Social engineering attacks do not rely on technical vulnerabilities or undiscovered malware. Instead, they exploit human trust — impersonating colleagues, IT staff, or vendors to manipulate employees into granting access. They are among the most effective attack methods precisely because no software patch can fix human judgement.
The Levi's breach follows a damaging wave of socially-engineered attacks on major retailers last year, demonstrating that the method has become a go-to playbook for sophisticated threat actors.
How hackers brought Marks & Spencer to its knees
The most instructive recent case is Marks & Spencer, one of the UK's largest and most recognisable retailers. The successful breach was not caused by unseen malware or a flaw in M&S's cyber defences. The attackers simply impersonated an M&S employee over the phone and called Tata Consultancy Services (TCS), the IT firm providing the retailer's help desk support.
That single call was enough. The hackers persuaded TCS to reset a password, which allowed them to bypass multi-factor authentication and move freely inside M&S's network. Once in, they harvested sensitive data across critical systems before deploying DragonForce ransomware in a double extortion attack — exfiltrating data first, then encrypting it to maximise leverage.
The consequences were severe. Staff were forced to revert to manual, pen-and-paper tracking of the retailer's complex supply chains, leading to empty shelves in stores and weekly losses of £40 million. The total cost to Marks & Spencer is estimated at between £270 million and £440 million.
Harrods and the Co-op suffered similar socially-engineered breaches in the same period, underlining that the method is being used systematically across the retail sector.
Why retail is a prime target
Retailers are attractive targets for several reasons. They hold large volumes of payment data and customer records, run complex multi-vendor supply chains with many external access points, and operate help desks — often outsourced — that are conditioned to be helpful and to reset credentials quickly. That culture of customer service can be turned against the organisation when an attacker exploits it.
The outsourcing of IT support in particular creates a social engineering vulnerability: a help desk operative working for a third-party provider may not know the employee they are speaking to, making impersonation easier and verification harder.
What can organisations do?
The M&S case and the Levi's breach point to the same set of protective measures:
- Verify before you reset. Any password reset or credential change requested by phone or message should require verification through a second, trusted channel — not just the caller's word. Help desk staff, whether in-house or outsourced, need clear protocols and the authority to refuse unverified requests.
- Treat MFA bypass as a red line. Multi-factor authentication is only effective if it cannot be circumvented through social engineering. Processes that allow MFA to be reset or disabled via a single phone call undermine the entire control.
- Extend security training beyond IT. Social engineering targets whoever is most accessible and most trusted — including help desk staff at outsourced providers, finance teams, and operations managers. Security awareness training needs to reach all of these groups, not just internal technical staff.
- Limit third-party access. Vendors and outsourced providers should hold only the minimum level of access required for their role, with that access logged, monitored, and time-limited where possible.
The broader pattern
The Levi's breach is the latest in a growing list of high-profile organisations undone not by a zero-day exploit or sophisticated malware, but by a phone call or a convincing message. As threat actors increasingly use AI tools to refine their impersonation and reconnaissance, the bar for a convincing social engineering attack continues to fall.
For organisations that have invested heavily in technical defences, the uncomfortable lesson from Levi's, M&S, and others is that the weakest point in their security posture may not be their software — it may be their help desk.
