Levi’s Breach Started With IT Helpdesk Impersonation

eSecurity Planet · High sophistication
Last updated August 11, 2026

Levi Strauss reported that an unauthorized party used social-engineering to compromise three employees’ company-issued computers and steal corporate data. Reporting tied the incident to a wider campaign where attackers impersonated IT help desks using spoofed phone numbers and fraudulent websites to capture employee passwords and two-factor authentication codes. The company says customer data was not affected and the investigation is ongoing.

How the attack worked

Levi Strauss reported that an unauthorized party used social engineering to compromise three employees' company-issued computers and steal corporate data. This incident was connected to a wider campaign in which attackers impersonated IT help desks, using spoofed phone numbers and fraudulent websites to obtain employee passwords and two-factor authentication (2FA) codes. According to reporting, attackers built customized phishing infrastructure and targeted more than 200 organizations in roughly five weeks, suggesting a repeatable, scaled operation rather than a one-off attempt.

The core mechanism was simple but effective: a phone call posing as internal IT support, paired with a fraudulent website designed to look like a legitimate login or verification portal. Employees who answered the call and followed the instructions were guided to enter their credentials and 2FA codes, giving attackers the access they needed.

Why it succeeded

This approach worked because it exploited trust in a familiar, low-friction interaction: a support call about an account issue. Spoofed caller ID numbers made the calls appear legitimate, and the fraudulent websites were built to mimic real verification flows closely enough to pass a quick glance. Once an employee is compromised, an attacker may be able to operate through legitimate accounts, making malicious activity harder to distinguish from normal use.

What to watch for

  • Unexpected calls from someone claiming to be IT support, especially ones pressuring immediate action
  • Requests to visit a link provided by the caller rather than a known internal portal
  • Any request, by phone or web form, to share a password or 2FA code
  • A caller staying on the line while you complete a

Key findings

  • Levi Strauss said an attacker used social engineering to access three employees’ company computers and steal corporate data.
  • Levi Strauss stated it contained the access, opened an investigation, and hired outside cybersecurity experts; it also said customer data was not affected.
  • Reuters and Google described a broader campaign using fake IT help desk identities, spoofed phone numbers, and fraudulent websites to steal passwords and 2FA codes.
  • Attackers reportedly built customized phishing infrastructure and targeted more than 200 organizations in roughly five weeks.

Who’s being targeted

  • Commonly targeted roles: All employees, Executive leadership, Finance and payments teams, IT helpdesk / service desk, HR and operations.
  • Affected industries: Apparel and retail, Financial services (hedge funds, private equity), Technology, Real estate / online marketplaces.
  • Attack channels: vishing, website.
  • Impersonated: IT help desk / internal support, IT help desk portal / single sign-on login page, IT help desk.

Red flags to watch for

  • Unexpected support call pressuring immediate action
  • Caller ID/number can be spoofed and should not be trusted alone
  • Request for passwords or 2FA codes (legitimate IT should not ask for these)
  • Login page reached from an untrusted or unexpected link
  • Lookalike website or unusual URL
  • Prompts for 2FA code outside the normal sign-in flow
  • Support asks you to use a link they provide instead of known internal portals
  • The caller stays on the line to prompt you for codes in real time
  • Any request to share passwords or 2FA codes
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers access Levi Strauss employee computers?

Levi Strauss said an attacker used social engineering to access three employees' company computers and steal corporate data, tied to a broader campaign impersonating IT help desks.

What tactics did the attackers use to steal credentials?

Reuters and Google described a campaign using fake IT help desk identities, spoofed phone numbers, and fraudulent websites to capture employee passwords and two-factor authentication codes.

Was customer data affected in the Levi Strauss incident?

Levi Strauss stated that customer data was not affected, and the company contained the access, opened an investigation, and hired outside cybersecurity experts.

How many organizations were targeted in this campaign?

Attackers reportedly built customized phishing infrastructure and targeted more than 200 organizations in roughly five weeks.

Read the video transcript

Levi’s breach started with three employees answering one thing: a fake IT help desk call. The script sounds legit: “Hi, this is the IT help desk, there’s an access issue on your account, I just need to verify your login and 2FA code.” The number even looks internal, but Google found these callers were using spoofed phone numbers and fake IT identities across more than 200 companies. Here’s the trap: while you’re on the call, they text or email you a link to an 'IT Support Verification Portal'. The page looks like our single sign-on, but the URL is slightly off. You type your username, password, then your 2FA code, and their fraudulent website quietly captures everything. Here’s your move: if you ever get an unexpected IT help desk call asking for a login or 2FA, hang up and contact IT using our official channel yourself, if it’s real, they’ll already know what you’re talking about.

Similar attacks

Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
Levi’s Breach Tied to Phone-to-Phish Workflow

Levi’s Breach Tied to Phone-to-Phish Workflow

Levi Strauss disclosed a breach after attackers used social engineering to access three employees’ work computers and steal some corporate data. Separately, reporting and Google’s tracking describe a broader campaign where criminals call employees while posing as coworkers or IT, then send them to…

August 10, 2026
Phishing Hits M365; Deepfake Vishing Targets Funds

Phishing Hits M365; Deepfake Vishing Targets Funds

The roundup describes real social-engineering incidents: a phishing email that led an employee to enter credentials on a fake Microsoft 365 login page, and a wave of voice-phishing attempts against major hedge funds using voice-mimicking technology. Both incidents show practical lures that can be…

August 7, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay codes in real time, SIM swapping, and stealing session cookies so MFA isn’t needed again. It also cites known incidents (e.g., Uber 2022 MFA…

July 29, 2026