Visualização de leitura

Levi Strauss Hit by Cyberattack, Corporate Files Accessed

Levi Strauss cyberattack

Levi Strauss cyberattack has exposed certain corporate information after an unauthorized third party gained access to company files through compromised employee computers, according to a filing with the U.S. Securities and Exchange Commission. Levi Strauss & Co. said it recently detected a cybersecurity incident involving unauthorized access to three company-issued computers. The company said the access was enabled through social engineering techniques, allowing the attackers to reach company files. According to the filing, the company initiated its response protocols after detecting the incident and implemented containment measures. It also launched an investigation that remains ongoing and engaged third-party cybersecurity experts to assist with the response.

Levi Strauss Cyberattack Investigation Remains Ongoing

Based on preliminary findings, Levi Strauss said it believes certain corporate information was accessed and exfiltrated during the incident. However, the company said its rapid response efforts successfully contained and terminated the unauthorized access. The company also stated that no consumer data had been impacted as of the date of the filing. Levi Strauss said the incident has not interrupted its business operations and that, based on the information currently available, it does not believe the incident has had or is reasonably likely to have a material impact on its business strategy, operations, financial condition, or results of operations. The company said it has provided and will provide notifications to affected parties and applicable regulators as appropriate and in accordance with applicable law. Levi Strauss & Co., headquartered in San Francisco, is known for its Levi's denim brand. The company reported net revenues of $6.3 billion for 2025, up 4% compared with fiscal year 2024 and 7% on an organic basis. The company designs and markets jeans, casual wear and related accessories for men, women and children under the Levi's, Levi Strauss Signature, and Beyond Yoga brands. Its products are sold in approximately 120 countries through chain retailers, department stores, online sites, and approximately 3,300 retail stores and shop-in-shops.

Retail Cybersecurity Incidents Continue

The Levi Strauss cyberattack comes as several major retailers have reported cybersecurity incidents involving their own systems or third-party service providers. In the first week of August 2026, the De Bijenkorf cyberattack affected the Dutch luxury department store chain after an incident involving one of its external logistics partners. The disruption affected order processing, deliveries, returns, and refunds, while the company said there was no evidence that its own infrastructure had been compromised. In October 2025, Spanish fashion retailer Mango confirmed a Mango data breach after an external marketing service provider experienced unauthorized access to limited customer information. Mango said its corporate systems were not compromised and that financial or login details remained secure. The exposed information included customers’ first names, countries, postal codes, email addresses, and phone numbers. The company said last names, banking information, credit card details, and passwords were not affected. Retailers also faced law enforcement action following a series of attacks. In July 2025, the UK’s National Crime Agency arrested four people suspected of orchestrating cyberattacks against Marks & Spencer, Co-op, and Harrods. The suspects were detained in the West Midlands and London and faced charges under the Computer Misuse Act, blackmail, money laundering, and involvement in an organized crime group. Meanwhile, in May 2025, Victoria’s Secret took down its U.S. website and some in-store services following what it described as a Victoria’s Secret security incident. The company said the precautionary shutdown was intended to address the incident while its team worked to restore operations. Its Victoria’s Secret and PINK stores remained open. The latest incident involving Levi Strauss adds another case to a growing series of cybersecurity incidents affecting major retailers, with the company continuing its investigation into the access and information involved.

Taiwan Flags Five Major Cyber Risks After 726 Security Incidents in 2025

Taiwan cyber risk

Taiwan’s digital security authorities have identified five major areas of concern following hundreds of reported cybersecurity incidents involving government agencies in 2025. According to Taiwan’s Ministry of Digital Affairs, the country recorded 726 cybersecurity incidents this year, highlighting ongoing Taiwan cyber risk challenges tied to ransomware, fake software, supply chain weaknesses, and social engineering attacks. The Administration for Cyber Security said the total number of reported cases declined slightly compared to 2024, with 29 fewer incidents recorded year over year. However, officials warned that attack methods continue to expose weaknesses across government systems and digital infrastructure.

Cybersecurity Incidents in Taiwan 

As reported by CNA and cited by UDN, most cybersecurity incidents were categorized as low-level threats under Taiwan’s classification system. However, authorities stressed that even minor breaches can create broader operational and national security concerns if left unresolved.  Under Taiwan’s cybersecurity framework, incidents are divided into four levels based on their impact on confidentiality, integrity, and system availability. Level 1 incidents accounted for 87.33% of all reports in 2025, while Level 2 incidents represented 9.78%. Level 3 incidents made up 2.89% of the total. No Level 4 incidents — the most severe category — were reported during the year.  Unauthorized access remained the most common issue among reported cybersecurity incidents, accounting for 68.6% of all cases. Equipment-related failures represented 15.43% of incidents, while denial-of-service attacks accounted for 4.96%. Website attacks made up another 2.48% of reported cases.  Following a review of cyber threat patterns and incident reports from government agencies, Taiwan’s Administration for Cyber Security identified five major Taiwan cyber risk trends that officials believe require immediate attention. 

Fake Messaging Apps Raise Taiwan Cyber Risk

One of the biggest cybersecurity risks highlighted by the administration involved fake communication software distributed through unofficial websites. According to UDN, some users unknowingly downloaded counterfeit messaging applications after replacing old devices or setting up new computers. Authorities said these downloads allowed attackers to install backdoor malware capable of compromising systems and sensitive information. The administration urged government agencies to implement stricter procedures for system modifications and software installations. Officials recommended that all software, hardware, and application installations receive prior approval before being used within agency systems. The administration warned that unofficial downloads continue to create major Taiwan cyber risk exposure across public sector networks.

Ransomware Tactics Become More Sophisticated

The second major concern centered on ransomware groups using customized software drivers to infiltrate systems and evade security detection tools. Authorities noted that attackers are becoming more advanced in bypassing conventional endpoint security measures. To reduce the likelihood of future cybersecurity incidents, the administration advised agencies to regularly scan websites for vulnerabilities, apply timely fixes, deploy web application firewalls, and ensure endpoint protection software remains updated. The ministry emphasized that outdated security tools and delayed patch management continue to increase Taiwan's cyber risk across both government and critical infrastructure networks.

Weak Supply Chain Security Creates Additional Exposure 

Supply chain vulnerabilities were identified as the third major cybersecurity threat. Officials cited one case in which a maintenance contractor installed remote desktop software on a website server. Hackers later gained access to the system after successfully guessing the password linked to the remote access tool.  The incident highlighted growing concerns about third-party vendors and contractor oversight. According to the administration, external maintenance work can create hidden entry points for cybercriminals if agencies fail to maintain strict security controls. The administration said agencies should strengthen supervision of vendors, improve password management practices, and enforce tighter restrictions on remote access systems to reduce Taiwan's cyber risk tied to supply chain operations. 
❌