Levi Strauss alerts customers about cyberattack

Published:

Cyber Warriors Conclave — nine editions, one cyber safe nation

Levi’s Online Store Security Incident: Personal Information and Payment Details Potentially Compromised

Levi’s Online Store Hit by Credential-Stuffing Attack, 72,000 Accounts Affected

Levi’s, the iconic denim jeans maker, recently disclosed that their online store was targeted in a cyberattack that compromised the personal information of over 72,000 accounts. The security incident, identified on July 13th, involved an automated credential-stuffing attack that may have exposed order history, names, emails, and stored addresses of affected customers.

Additionally, partial payment details such as the last four digits of card numbers, card types, and expiration dates were potentially viewed by the threat actor, especially for customers who had saved payment methods on the platform. Despite this breach, Levi Strauss assured customers that no fraudulent purchases were made using the compromised information, as their systems require secondary authentication for payment methods.

The company attributed the incident to an automated credential-stuffing attack, a common tactic where cybercriminals use stolen credentials from one platform to gain unauthorized access to accounts on another platform. In response, Levi Strauss enforced a forced password reset for all affected accounts, urging customers to create strong and unique passwords to enhance security.

This breach comes amidst a wave of cyberattacks targeting online platforms, with streaming service Roku also recently falling victim to a credential-stuffing attack affecting 576,000 accounts. As cybersecurity threats continue to evolve, it is crucial for users to remain vigilant and take proactive measures to safeguard their online accounts.

Cyber Warriors Conclave Chapter X — Beyond the Ballroom

Related articles

Recent articles

Media Streaming Devices with Open ADB Ports Expose Home Networks to Cyber Threats

Media streaming devices, particularly those with open Android Debug Bridge (ADB) ports, are exposing home networks to significant cybersecurity threats. According to a report...

PaperCut Vulnerabilities CVE-2026-81578 and CVE-2026-82078 Added to CISA KEV Database

Advisory Date: August 28, 2026Last Updated: August 31, 2026 Recent vulnerabilities have been identified in PaperCut products, specifically affecting versions of PaperCut MF and PaperCut...

Microsoft Warns of TerminalFix Campaign Using Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor

Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal...

Microsoft Security August 2026 Update Introduces Enhanced AI Management Tools and Threat Intelligence

As organizations increasingly integrate AI agents into their operations, the need for robust cybersecurity measures has never been more critical. The latest updates from...