Tech

Levi Strauss corporate data stolen in cyberattack

Published

on

No consumer data was impacted in the hack, the company clarified in a regulatory filing.

US apparel maker Levi Strauss said that hackers gained access to three of its workers’ company-issued computers using social engineering techniques, joining a growing list of major business victimised by the onslaught of cyberattacks, now often boosted by AI.

The admission comes just days after hackers launched a wave of attacks against Wall Street businesses using voice phishing, or vishing, where criminals mimic voices to trick victims into divulging sensitive data.

In a regulatory filing today (7 August), Levi said that an unauthorised third party stole “certain corporate information” after accessing company files through the hacked employees. It clarified that no consumer data was impacted.

Advertisement

The company said it managed to contain the incident and notify affected parties and regulators. An investigation into the matter is ongoing for which the company has hired third-party cybersecurity experts. Levi said it did not experience any interruption in business operations as a result.

Social engineering is a hacking technique where bad actors trick unsuspecting people using fake online identities, with increasingly advanced AI tools giving criminals a cheap and efficient way to identify and exploit vulnerabilities.

A recent report from the UK’s AI Security Institute (AISI) found that Anthropic and OpenAI’s new agentic AI models engaged in social engineering in a test environment to pressure its maintainer into approving malicious code. However, these attempts were unsuccessful, as a human maintainer refused to approve the code.

AISI said that the AI models it tested showed “signs of novel, potentially deceptive behaviours” at levels it did not expect. In different testing environments, these models escaped their sandboxes and hacked real organisations, raising alarm across the industry.

Advertisement

Google Threat Intelligence Group, in its own research, found a cybergroup using vishing to target employees from financial services or cloud companies by posing as IT helpdesk staff facilitating urgent work. Often employees were contacted using their personal mobile devices, the group noted.

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version