HackingStolen CredentialsCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALSLowContained
Levi Strauss & Co.
bd_da3a3e26c0353b71 · schema v1 · pii pii-v1
Full breach record for Levi Strauss & Co. →Levi Strauss & Co. detected a credential stuffing attack on June 13, 2024, where bad actors used compromised credentials from other sources to attempt access to Levi.com accounts. The company issued forced password resets and deactivated affected credentials. Affected data included name, email, addresses, order history, and partial payment card information (last 4 digits, type, expiration). No fraudulent purchases were detected.
California clockDiscovered Jun 13, 2024 → Notified Jun 21, 20248d ✓ CA 60-day OK8 days discovery → filing
This filing is one of 8 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (7) · sorted by filing gap
- bd_3b1eebcb107db0adOregon State AGfiled 2024-06-21Verified
- bd_af1f821586c29af7Washington State AGfiled 2024-06-21Verified
- bd_bef76f3f16d22f20Indiana State AGfiled 2024-06-21Verified
- bd_c9110f3671bb06deNew Hampshire State AGfiled 2024-06-21Verified
Show 3 more filings ↓Show fewer ↑up to 1d gap
- bd_7e8e7bdd4378db66Maine State AGfiled 2024-06-22(1d gap)Verified
- bd_ba58543d29f42753Montana State AGfiled 2024-06-20(1d gap)Candidate
- bd_d5e768930b4a7060Vermont State AGfiled 2024-06-20(1d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-587315
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jun 21, 2024
- Raw hash
- abffc260ed4a94c008df298d2236c69ca1f75cd48e20e7c8e02b86c75cebf11a
Reporting entity
- Name
- Levi Strauss & Co.norm: levi strauss
- Domain
- levi.com
Victim entity
- Name
- Levi Strauss & Co.norm: levi strauss
- Domain
- levi.com
Incident
- Discovered
- Jun 13, 2024
- Materiality determined
- —
- Notification sent
- Jun 21, 2024
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTCREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1110.003 Credential Stuffing
- Threat actor
- External
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 8 days(8 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 8d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Jun 13, 2024→ Notified: Jun 21, 20248d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.