Levi’s Breach Tied to Phone-to-Phish Workflow

The Register Security · Medium sophistication
Last updated August 11, 2026

Levi Strauss disclosed a breach after attackers used social engineering to access three employees’ work computers and steal some corporate data. Separately, reporting and Google’s tracking describe a broader campaign where criminals call employees while posing as coworkers or IT, then send them to fake login pages to capture passwords and MFA codes.

What Happened

Levi Strauss disclosed a breach after attackers used social engineering to gain access to three employees' work computers. From there, the intruders accessed and exfiltrated what the company described only as certain corporate information. Levi's said it detected the intrusion, started incident response procedures, and managed to cut off the unauthorized access.

Separately, reporting describes a much broader campaign affecting more than 200 organizations. In that workflow, attackers phone employees on their personal mobiles while posing as colleagues or IT support staff, then direct them to spoofed login pages designed to harvest credentials and multi-factor authentication codes. Google researchers are tracking several crews involved in this wider campaign, which may sit under an umbrella group dubbed UNC6671. There is no confirmation that this group was responsible for the Levi's incident specifically.

Why This Approach Works

Calling a personal mobile number bypasses corporate spam filters and security awareness training that focuses mostly on email. A caller who sounds confident and claims to represent IT support or a familiar colleague can create urgency around a supposed account issue, pushing the target to act quickly rather than verify. Once the victim is directed to a convincing but fake login page, entering both a password and an MFA code hands attackers everything needed to bypass standard multi-factor protections.

Red Flags to Watch For

  • An unsolicited call to a personal mobile number from someone claiming to be internal IT or a colleague
  • Pressure to visit a specific login page provided during the call rather than a known, bookmarked company URL
  • Any request to read out or enter an MFA code as part of resolving an account issue
  • Requests that bypass normal IT ticketing or verification procedures
  • Any interaction that results in someone else gaining access to your work computer

Building Resistance

Employees across all roles, including IT/helpdesk, finance, legal, and executives, should treat unsolicited IT support calls to personal phones as suspicious and verify the request through official channels before taking any action. Passwords and MFA codes should never be entered into a site reached via a link or instructions from an unexpected caller; instead, navigate to company systems using known, saved URLs.

The Levi's case also shows the value of fast detection and response: even after attackers gained initial access, the company was able to identify the intrusion and cut off unauthorized access before it escalated further. Reinforcing a culture where employees report suspicious calls or login prompts immediately, without fear of blame, can materially reduce the impact of these phone-to-phish attacks.

Key findings

  • Levi Strauss said attackers used social engineering to access three employees’ work computers and exfiltrate “certain corporate information.”
  • Levi’s reported it detected the intrusion, began incident response, and “managed to cut off the unauthorized access.”
  • A wider campaign reportedly targeted 200+ organizations, using phone calls to personal mobiles while impersonating colleagues or IT support.
  • The broader workflow directs victims to “spoofed login pages designed to harvest credentials and multi-factor authentication codes.”
  • Google researchers are tracking multiple crews possibly under an umbrella group called “UNC6671,” but there is no confirmation it was responsible for Levi’s incident.

Who’s being targeted

  • Commonly targeted roles: All employees, IT/Helpdesk, Finance, Legal, Executives.
  • Affected industries: Manufacturing, Healthcare, Insurance, Technology, Hospitality, Finance, Legal services.
  • Attack channels: vishing, website, social_engineering.
  • Impersonated: Internal IT support staff (or a colleague), Unspecified (social engineering used to gain access).

Red flags to watch for

  • Unsolicited call to a personal mobile number claiming to be internal IT
  • Pressure to use a specific login page provided by the caller
  • Asked to provide/enter an MFA code as part of the “fix”
  • Unexpected requests to change account settings or access systems
  • Requests that bypass normal IT ticketing/verification
  • Any request that results in someone else gaining access to your workstation
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers breach Levi Strauss?

Levi Strauss said attackers used social engineering to access three employees' work computers and exfiltrate certain corporate information.

What is the broader campaign linked to this attack?

A wider campaign reportedly targeted more than 200 organizations by calling employees on personal mobiles while posing as colleagues or IT support, then directing them to spoofed login pages that harvest credentials and MFA codes.

Was a specific threat group confirmed to be behind the Levi's incident?

No. Google researchers are tracking multiple crews possibly under an umbrella group called UNC6671, but there is no confirmation this group was responsible for the Levi's incident.

How did Levi's respond to the breach?

Levi's said it detected the intrusion, began incident response procedures, and managed to cut off the unauthorized access.

Read the video transcript

Levi’s got breached because someone answered the wrong “IT support” call. Same playbook is hitting 200-plus companies. The script goes like this: they call your personal mobile, pose as a coworker or IT, warn about an account issue, then walk you to a login page to “fix” it and grab your password and MFA code. In the Levi’s case, social engineering got attackers onto three employees’ work computers and let them exfiltrate corporate data, until Levi’s spotted it and cut off access. Aha moment: if “IT” calls your personal phone and tells you where to log in, hang up and report it to our security team immediately. Real IT will never need your MFA code over the phone.

Similar attacks

Levi’s Breach Started With IT Helpdesk Impersonation

Levi’s Breach Started With IT Helpdesk Impersonation

Levi Strauss reported that an unauthorized party used social-engineering to compromise three employees’ company-issued computers and steal corporate data. Reporting tied the incident to a wider campaign where attackers impersonated IT help desks using spoofed phone numbers and fraudulent websites…

August 10, 2026
Wall Street Hit by Helpdesk Impersonation Calls

Wall Street Hit by Helpdesk Impersonation Calls

A phone-first extortion campaign targeted dozens of major U.S. financial firms by calling employees and posing as corporate help-desk staff. Victims were pushed to “update” passkeys/MFA and sent to fake login pages; attackers captured passwords and MFA codes in real time to take over accounts and…

August 7, 2026
Fake IT Helpdesk Calls Steal MFA at Finance Firms

Fake IT Helpdesk Calls Steal MFA at Finance Firms

A criminal group tracked as UNC6671 called employees while pretending to be their company IT helpdesk, creating urgency around “mandatory” security changes. Victims were directed to lookalike login pages to “enable passkeys” or “update MFA,” allowing attackers to steal passwords and capture…

August 7, 2026
Fake IT Helpdesk Calls Hit Wall Street Firms

Fake IT Helpdesk Calls Hit Wall Street Firms

A ransom-focused hacking group targeted major U.S. financial and other firms by calling employees on their personal phones while impersonating the company help desk. Victims were pushed to “update passkeys or multifactor authentication” and sent to look‑alike websites designed to steal passwords…

August 6, 2026
Hotel Wi‑Fi Lures and Entra Vishing Hit Users

Hotel Wi‑Fi Lures and Entra Vishing Hit Users

The article reports real-world social engineering operations, including a hotel Wi‑Fi campaign that pushed fake updates and device-code phishing to steal Microsoft 365 access. It also describes an alleged Microsoft Entra vishing campaign tied to data theft claims at Brinks Home, reinforcing the…

August 7, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026