Levi Strauss & Co.
bd_da3a3e26c0353b71 · schema v1 · pii pii-v1
Full breach record for Levi Strauss & Co. →4 incidents on fileLevi Strauss & Co. detected a credential stuffing attack on June 13, 2024, where bad actors used compromised credentials from other sources to attempt access to Levi.com accounts. The company issued forced password resets and deactivated affected credentials. Affected data included name, email, addresses, order history, and partial payment card information (last 4 digits, type, expiration). No fraudulent purchases were detected.
J jump to incidentP pin to compareR raw source
Incident timeline
Jun 13, 2024
Begins
Jun 13, 2024
Discovered
Jun 21, 2024
Filed
vs. sector median
6 wks faster
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- Oregon State AGbd_3b1eebcb107db0ad2024-06-21Verified
- Washington State AGbd_af1f821586c29af72024-06-21Verified
- Indiana State AGbd_bef76f3f16d22f202024-06-21Verified
- New Hampshire State AGbd_c9110f3671bb06de2024-06-21Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- Maine State AGbd_7e8e7bdd4378db662024-06-22 · +1dVerified
- Montana State AGbd_ba58543d29f427532024-06-20 · +1dCandidate
- Vermont State AGbd_d5e768930b4a70602024-06-20 · +1dVerified
Filing propagation · 8 filings · 8 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.