What has happened to Levi’s
Levi Strauss, the company behind the famous Levi’s jeans, has confirmed that some criminals got into its internal computers and stole company information. It reported it on Friday 7 August in an official document that companies in the United States are required to file when they suffer this kind of incident.
According to the company itself, the attackers did not get in by breaking down any technological barrier. They tricked three employees into giving them access to their work computers. This way of attacking is called “social engineering”, although to understand each other it is easier to call it a con or scam: instead of forcing the door, they convince someone to open it.
Levi’s says it detected the problem quickly and contained it, that its normal activity did not stop and that there are no signs that customer data was touched. What they took was “certain corporate information”, with no further details. The investigation remains open, the company has hired external security experts and, for now, no group has claimed responsibility for the attack.
A wave of fake calls to companies
What is striking is that Levi’s is not an isolated case. Days before, on 5 August, the Reuters agency reported that several large Wall Street firms, the financial heart of the United States, had suffered very similar attack attempts. In those cases, the criminals called employees by phone pretending to be from the company’s own IT service, with an urgent excuse: “there is a problem with your account, give me your data to fix it”.
This technique has a name: it is called “vishing”, a mix of “voice” and “fishing”. The idea is the same as the fake email that promises a prize, but over the phone and with more pressure. The groups that use it, such as the well-known “Scattered Spider”, have managed to get into many large companies in recent years. Google itself has warned that there are organized gangs dedicated to this, and the FBI has been alerting for weeks to the rise of these tricks.
Retailers are a common target. So far this year, the Dutch chain De Bijenkorf, the Spanish Mango, The North Face, Harrods, Marks & Spencer or The Co-op have suffered similar incidents. Levi’s, which has almost 3,300 stores and about 19,000 employees, now joins that list.
Why this affects you
It may seem like a big-company problem, but it is not. The same trick they use against Levi’s employees they use every day against ordinary people: calls from a “bank” asking for the confirmation code, messages from a “courier company” asking for a payment, or notices from “Microsoft” that your computer has a virus and it must be fixed right away.
The golden rule is simple: no legitimate person will ask you by phone for your passwords, your codes or your money. A real bank, a real company, does not need you to tell it your password to “verify your account”. If someone calls you urgently asking for data, the best thing is to hang up and call yourself the company’s official number, the one that appears on its website or on your card.
Haste is the scammer’s best ally
Criminals create a sense of urgency on purpose: “if you do not do it now, you lose the money”, “it is an emergency”, “they are going to block your account”. That haste is what makes people make mistakes. Whoever really calls has no hurry: the only one in a hurry is the one who wants you to act without thinking.
What to do if a suspicious call reaches you
If you receive a strange call, do not give any data. Write down the name of the company they claim to be, hang up and check on your own. And remember: the security updates of your devices are like vaccines for the computer: they do not prevent all problems, but they make it much harder for something bad to happen to you. Keeping them up to date is one of the best protections you have, and it is free.
The conclusion
The Levi’s case shows that the most dangerous attacks do not always use very advanced technology: many times they only need a call and a little pressure. The good news is that that same human weakness can be turned into your strength. If you learn to detect the haste, the urgency and the request for data, you have already won half the battle. And when you have doubts, remember the phrase the experts repeat: when in doubt, hang up and check.






