Levi Strauss & Co.
ent_019e220ae143eadec23835fa2e3374a2
Disclosures
11
SEC 8-K · State AG · 10 jurisdictions
Multi-filing incidents
1
incidents joining 2+ filings here
Max affected reported
72,231
nationwide · State AG ME
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Levi Strauss & Co.
- Normalized
- levi strauss— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- MB0UERO0RDFKU8258G77
- SEC EDGAR CIK
- 0000094845
- Domain
- None on record
Disclosure history (11)newest first
- FEDERALSEC 8-Kas victim2026-08-07
Levi Strauss & Co. filed an 8-K on August 7, 2026, reporting a cybersecurity incident where an unauthorized third party gained access to corporate files via social engineering targeting three employees. The company states that corporate information was accessed and exfiltrated, but no consumer data was impacted. The incident is contained, and third-party experts were engaged.
- Indiana State AGas victim2025-03-31
Levi Strauss & Co reported a data breach to the Indiana Attorney General. The breach occurred on 2025-03-11 and was reported on 2025-03-31. 1 Indiana residents were affected. 217 individuals affected in total.
- Maine State AGas victim2024-06-22
Levi Strauss & Co. reported a credential stuffing attack on June 13, 2024, affecting 72,231 individuals, including 75 Maine residents. Attackers used stolen credentials to access accounts, viewing order history, names, emails, addresses, and partial payment info. LS&Co forced password resets and deactivated compromised accounts. No fraudulent purchases were detected.
- Oregon State AGas victim2024-06-21
Levi Strauss & Co. reported a data breach to the Oregon Attorney General. The breach was reported on 2024-06-21. 72,231 individuals were affected.
- Washington State AGas victim2024-06-21
Levi Strauss & Co. reported a credential stuffing attack on June 13, 2024, where bad actors used stolen credentials from third-party breaches to access user accounts. The incident affected 640 Washington residents. Compromised data included names, emails, addresses, order history, and partial payment card details. LS&Co forced password resets and deactivated compromised accounts.
- Indiana State AGas victim2024-06-21
Levi Strauss & Co reported a data breach to the Indiana Attorney General. The breach occurred on 2024-06-13 and was reported on 2024-06-21. 706 Indiana residents were affected. 72,231 individuals affected in total.
- New Hampshire State AGas victim2024-06-21
Levi Strauss & Co. notified the NH Attorney General of a credential stuffing attack detected on June 13, 2024. Attackers used valid credentials from a third-party breach to access 123 NH residents' accounts on levi.com. LS&Co deactivated compromised accounts and forced password resets. Exposed data likely included basic PII; no payment data was compromised.
- California State AGas victim2024-06-21
Levi Strauss & Co. detected a credential stuffing attack on June 13, 2024, where bad actors used compromised credentials from other sources to attempt access to Levi.com accounts. The company issued forced password resets and deactivated affected credentials. Affected data included name, email, addresses, order history, and partial payment card information (last 4 digits, type, expiration). No fraudulent purchases were detected.
- Montana State AGas victim2024-06-20
Levi Strauss & Co. detected a credential stuffing attack on June 13, 2024, where bad actors used stolen credentials from third-party breaches to access user accounts. The company forced password resets and deactivated compromised accounts. Affected data included names, emails, addresses, order history, and partial payment card details. No fraudulent purchases were initiated.
- Vermont State AGas victim2024-06-20
Levi Strauss & Co notified Vermont consumers of a credential stuffing attack detected on June 13, 2024. Attackers used stolen credentials from other breaches to access user accounts on levis.com. Affected data included names, emails, addresses, order history, and partial payment card details. LS&Co forced password resets and deactivated compromised accounts. No fraudulent purchases were detected.
- Massachusetts State AGas victim2023-05-18
Levi Strauss & Co. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2023-05-18. 1 Massachusetts residents were affected. The report records the breach type as electronic.