HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICCREDENTIALSLowContained
Levi Strauss & Co.
bd_c9110f3671bb06de · schema v1 · pii pii-v1
Full breach record for Levi Strauss & Co. →Levi Strauss & Co. notified the NH Attorney General of a credential stuffing attack detected on June 13, 2024. Attackers used valid credentials from a third-party breach to access 123 NH residents' accounts on levi.com. LS&Co deactivated compromised accounts and forced password resets. Exposed data likely included basic PII; no payment data was compromised.
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_3b1eebcb107db0adOregon State AGfiled 2024-06-21Verified
- bd_af1f821586c29af7Washington State AGfiled 2024-06-21Verified
- bd_bef76f3f16d22f20Indiana State AGfiled 2024-06-21Verified
- bd_da3a3e26c0353b71California State AGfiled 2024-06-21Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_7e8e7bdd4378db66Maine State AGfiled 2024-06-22(1d gap)Verified
- bd_ba58543d29f42753Montana State AGfiled 2024-06-20(1d gap)Candidate
- bd_d5e768930b4a7060Vermont State AGfiled 2024-06-20(1d gap)Verified
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/levi-strauss-20240621.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 21, 2024
- Raw hash
- fdabab93e411ef7830ec3ea789fc3dc3e2961073d36cb904c727b8bfde6afc4c
Reporting entity
- Name
- Levi Strauss & Co.norm: levi strauss
- Domain
- levi.com
Victim entity
- Name
- Levi Strauss & Co.norm: levi strauss
- Domain
- levi.com
Incident
- Discovered
- Jun 13, 2024
- Materiality determined
- —
- Notification sent
- Jun 21, 2024
- Affected individuals
- 123
- Data types
- IDENTITY_BASICCREDENTIALS
- Attack vector
- Phishing
- MITRE ATT&CK
- T1078 Valid AccountsT1114 Email Collection
- Threat actor
- ExternalFinancial
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.