When most business owners picture a cyberattack, they imagine hackers furiously typing code, exploiting a hidden software vulnerability, or deploying sophisticated malware against a company’s network.
The recent cybersecurity incident at Levi Strauss & Co. is an important reminder that attackers may choose a much simpler route.
They target the people who already have access.
On August 7, 2026, Levi Strauss & Co. disclosed a cybersecurity incident to the U.S. Securities and Exchange Commission. According to the company, an unauthorized third party used social engineering techniques that resulted in access to three employees’ company-issued computers.
That access was enough for the attacker to reach company files and remove certain corporate information from the environment.
And that should get the attention of every business owner.
What Happened at Levi Strauss?
Levi Strauss said it recently detected unauthorized access involving three employee computers.
Rather than describing the initial intrusion as the exploitation of a software vulnerability, Levi Strauss specifically identified social engineering as the method used to gain access.
Social engineering attacks are designed to manipulate people into doing something that benefits the attacker. That might mean providing login information, approving an authentication request, visiting a fake login page, granting remote access, or believing someone who is impersonating a trusted person.
Once the Levi Strauss incident was discovered, the company activated its incident response procedures, implemented containment measures, began an investigation, and brought in outside cybersecurity experts.
Preliminary findings indicated that certain corporate information had been accessed and exfiltrated.
There is some good news.
As of the company’s August 7 disclosure, Levi Strauss said it believed the unauthorized access had been successfully contained. The company also said it had not experienced an interruption to business operations and that its investigation had found no consumer data impacted at that point. The investigation remains ongoing.
The Biggest Lesson: Your Employees Are Part of Your Security Strategy
Businesses spend significant amounts of money protecting networks.
Firewalls. Endpoint security. Spam filtering. Antivirus software. Cloud security. Backups. Monitoring.
All of those tools matter.
But attackers know something else matters too:
Trust.
If an attacker can convince an employee that they are speaking with someone from IT, Microsoft, a vendor, their bank, their boss, or another trusted organization, they may be able to bypass security controls without having to technically “break” anything.
That is what makes social engineering so dangerous.
A legitimate employee already has access to systems the attacker wants. Instead of attacking the system directly, the criminal attempts to manipulate the employee into becoming the doorway.
And the attack may arrive somewhere employees are not expecting.
Social engineering is not limited to suspicious emails. NIST warns businesses that phishing-style attacks can arrive through email, text messages, social media and phone calls.
That means telling employees simply “don’t click suspicious links” is no longer enough.
What Would Your Employee Do If “IT” Called?
Imagine this happening at your company.
An employee receives a call.
The person on the other end knows their name. They know where they work. They may even know what software the company uses.
They say:
“We noticed a problem with your account. I need to verify your computer.”
The employee wants to help.
The caller sounds professional.
Maybe they create urgency. Maybe they direct the employee to a website. Maybe an MFA notification suddenly appears on the employee’s phone.
Would your employee know what to do?
More importantly:
Have you ever trained them for that exact situation?
Cybersecurity awareness cannot exist only in an employee handbook employees read during onboarding.
Employees need to understand what modern attacks actually look like.
Five Questions Every Business Should Ask After the Levi Strauss Incident
1. Are employees trained for more than email phishing?
Your team should recognize suspicious phone calls, text messages, fake login pages, unexpected MFA requests and people impersonating IT support.
Training should reflect the attacks businesses are facing today—not the attacks they faced five years ago.
2. Can employees independently verify someone claiming to be IT?
Create a simple policy.
If someone unexpectedly contacts an employee asking for access, passwords, authentication codes or security changes, the employee should verify that person through an approved communication channel before doing anything.
Employees should never feel pressured to bypass verification because a request sounds urgent.
3. Are you using the strongest MFA available?
MFA remains an important security layer, but not all MFA methods provide the same level of protection.
CISA recommends businesses move toward phishing-resistant MFA where possible, particularly for sensitive accounts, remote access and administrative users.
Security keys and other phishing-resistant authentication methods can make certain credential-stealing attacks significantly harder to complete.
4. Does every employee have access to only what they actually need?
If one account or workstation becomes compromised, the amount of damage an attacker can cause often depends on what that user can access.
Employees should have the permissions required to perform their jobs—but not unnecessary access to sensitive systems and data.
This is one reason access management and least-privilege policies matter.
5. Do you have a plan for what happens after someone makes a mistake?
Eventually, someone may click something they should not have clicked.
Someone may approve a login request.
Someone may answer a convincing phone call.
The difference between a security scare and a major incident can come down to how quickly your business responds.
Employees should know exactly who to contact when something feels wrong, and businesses should have an incident response process ready before the emergency happens.
Cybersecurity Is Not Just an IT Problem
The Levi Strauss incident illustrates something businesses cannot afford to ignore:
Technology alone cannot protect an organization.
Cybersecurity is a combination of technology, processes, monitoring, access controls, employee education and preparation. You need tools designed to stop attacks. You need people who recognize when something does not look right. And you need a plan for containing the problem quickly if an attacker does get through.
Levi Strauss is a major global company. According to its own disclosure, the incident involved access through just three employees’ company-issued computers. For a smaller organization, compromising even one employee could potentially create a serious problem.
Would Your Business Catch It?
The question is not whether your company is big enough for hackers to notice. It is whether your company is prepared when someone tries.
Would an employee recognize a fake IT call?
Would your security tools detect unusual activity?
Would compromised access be limited?
Could you quickly isolate an infected or compromised device?
Would your backups actually restore?
Does your team know what happens next?
Those are questions worth answering before an attacker answers them for you.
Engler IT Can Help You Stay Ahead of the Attack
Cybersecurity should not begin after a breach. Engler IT helps businesses build practical cybersecurity strategies that combine technology, monitoring, employee protection, data security, backup planning and incident preparedness. Because protecting your business is not just about putting more security tools in place.
It is about making sure the entire business is harder to compromise.
If you are not sure how your organization would respond to a social engineering attack, phishing attempt or compromised employee account, now is the time to find out.
Contact Engler IT to start the conversation about protecting your business before the next attack happens.

