Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Voice Phishing. Show all posts

Levi Strauss & Co. Confirms Hackers Stole Corporate Data in Cyberattack

Levi Strauss & Co. (Levi’s) has announced a cybersecurity incident involving an unauthorized third party who used social engineering to access the company's systems and exfiltrate corporate information from the systems of three employees. The clothing giant disclosed the incident in its filing with the U.S Securities and Exchange Commission (SEC). According to the SEC's investigation, certain corporate information was accessed and exfiltrated during the attack. 

Several employees were targeted by the attackers through social engineering, which gave them access to their systems without their consent. Levi Strauss has not disclosed the precise social engineering technique used by the threat actor, or whether the threat actor made any extortion demands, but this incident specifically affected three company-provided computers. Levi Strauss stated that its security teams responded quickly to contain and terminate the unauthorized access. 

According to Levi Strauss' preliminary investigation, it is not believed that customer information has been stolen. In addition, the company stated that the incident did not disrupt operations for the company. Levi Strauss stated in its SEC filing that, based on preliminary findings from the Company's investigation, it believes that some corporate information has been accessed and exfiltrated as a result of the incident. Levi Strauss expects the incident to have no material impact on the company's financial position or business based on its preliminary findings so far. Levi Strauss will provide additional notifications as additional information becomes available. 

The Levi Strauss & Co. (Levi’s) apparel company, one of the world's most recognizable companies, employs approximately 19,000 people and operates over 3,300 stores. The products are also available through third parties and online platforms. Levi Strauss has not identified the threat actor responsible for the intrusion or revealed whether the company received any extortion demands from the attacker. Unconfirmed reports suggest that the hacker may have been associated with UNC6671, a hacking group that has been associated with recent voice phishing attacks. 

According to Levi Strauss, the attribution has not been confirmed, and it remains unclear what tactics were employed in the attack. There is a general indication that the Levi Strauss incident occurred at the same time as a broader wave of voice phishing and social engineering attacks targeting major organizations. 

According to Google and other internet intelligence sources consulted by Reuters, ransom-seeking attackers were attempting to compromise victims through phone calls in recent weeks by targeting dozens of prominent financial institutions and other organizations in the United States. Levi Strauss was among more than 200 companies targeted with digital traps over the course of five weeks with the same intelligence. Levi Strauss has not confirmed the possible connection, and the attackers, the specific corporate information stolen, and the method of targeting employees are still under investigation. 

Despite the company's assertion that customer information was not compromised, the incident demonstrates the continuing threat posed by social engineering and phishing attacks. Organizations continue to be vulnerable when attackers can manipulate employees into providing access to corporate systems and information. 

In response to the attackers' attempt to gain access to the compromised computers, the company immediately responded and contained them. Levi Strauss has not reported any interruption to its business operations and does not believe the incident has, or is reasonably likely to have, a material impact on its financial or business position at this time. 

Despite the breach, Levi Strauss has not reported any operational impacts and continues to investigate the incident. Levi Strauss' incident illustrates the growing threat of voice-phishing and social engineering attacks against large corporations. Although the company has indicated that the customer data was not compromised, the ongoing investigation emphasizes the need for employee awareness, access controls, and rapid response to targeted cyberattacks to limit their impact.

CrowdStrike Report Reveals a Surge in AI-Driven Threats and Malware-Free Attacks

 

CrowdStrike Holdings Inc. released a new report earlier this month that illustrates how cyber threats evolved significantly in 2024, with attackers pivoting towards malware-free incursions, AI-assisted social engineering, and cloud-focused vulnerabilities. 

The 11th annual CrowdStrike Global Threat Report for 2025 details an increase in claimed Chinese-backed cyber activities, an explosion in "vishing," or voice phishing, and identity-based assaults, and the expanding use of generative AI in cybercrime. 

In 2024, CrowdStrike discovered that 79% of cyber incursions were malware-free, up from 40% in 2019. Attackers were found to be increasingly using genuine remote management and monitoring tools to circumvent standard security measures. 

And the breakout time — the time it takes a perpetrator to move laterally within a compromised network after gaining initial access — plummeted to 48 minutes in 2024, with some attacks spreading in less than a minute. Identity-based assaults and social engineering had significant increases until 2024. 

Vishing attacks increased more than fivefold, displacing traditional phishing as the dominant form of initial entry. Help desk impersonation attempts grew throughout the year, with adversaries convincing IT professionals to reset passwords or bypass multifactor authentication. Access broker adverts, in which attackers sell stolen credentials, increased by 50% through 2024, as more credentials were stolen and made available on both the clear and dark web. .

Alleged China-linked actors were also active throughout the year. CrowdStrike's researchers claim a 150% rise in activity, with some industries experiencing a 200% to 300% spike. The same groups are mentioned in the report as adopting strong OPSEC measures, making their attacks more difficult to track. CrowdStrike's annual report, like past year's, emphasises the growing use of AI in cybercrime.

Generative AI is now commonly used for social engineering, phishing, deepfake frauds, and automated disinformation campaigns. Notable AI initiatives include the North Korean-linked group FAMOUS CHOLLIMA, which used AI-powered fake job interviews to penetrate tech companies. 

Mitigation tips 

To combat rising security risks, CrowdStrike experts advocate improving identity security through phishing-resistant MFA, continuous monitoring of privileged accounts, and proactive threat hunting to discover malware-free incursions before attackers gain a foothold. Organisations should also incorporate real-time AI-driven threat detection, which ensures rapid response capabilities to mitigate fast-moving attacks, such as those with breakout periods of less than one minute. 

In addition to identity protection, companies can strengthen cloud security by requiring least privilege access, monitoring API keys for unauthorised use, and safeguarding software-as-a-service apps from credential misuse. As attackers increasingly use automation and AI capabilities, defenders should implement advanced behavioural analytics and cross-domain visibility solutions to detect stealthy breaches and halt adversary operations before they escalate.

Sophisticated Vishing Campaigns are Rising Exponentially Worldwide

 

Voice phishing, also known as vishing, is popular right now, with multiple active campaigns throughout the world ensnaring even savvy victims who appear to know better, defrauding them of millions of dollars. 

South Korea is one of the global regions hardest hit by the attack vector; in fact, a fraud in August 2022 resulted in the largest amount ever stolen in a single phishing case in the country. This transpired when a doctor sent 4.1 billion won, or $3 million, in cash, insurance, stocks, and cryptocurrency to criminals, showing how much financial harm one vishing scam can inflict.

According to Sojun Ryu, lead of the Threat Analysis Team at South Korean cybersecurity firm S2W Inc., sophisticated social engineering strategies used in recent frauds involve imitating region law enforcement officers, giving individuals a false sense of authority. Ryu will present a session on the topic, "Voice Phishing Syndicates Unmasked: An In-Depth Investigation and Exposure," at the upcoming Black Hat Asia 2024 conference in Singapore. 

Vishing attempts in South Korea, in particular, take advantage of cultural differences that allow even those who do not appear to be susceptible to such scams to be victimised, he claims. For example, in recent frauds, cybercriminals have posed as the Seoul Central District Prosecutor's Office, which "can significantly intimidate people," Ryu adds. 

By doing so and acquiring people's private data ahead of time, they are successfully intimidating victims into completing money transfers — sometimes in the millions of dollars — by convincing them that if they do not, they will suffer serious legal penalties. 

Vishing engineering: A blend of psychology and technology 

Ryu and his companion speaker at Black Hat Asia, YeongJae Shin, a threat analysis researcher who previously served at S2W, will focus their talk on vishing in their own nation. However, vishing scams identical to those seen in Korea appear to be sweeping the globe recently, leaving unfortunate victims in their wake.

Even savvy Internet users appear to fall for the law-enforcement frauds; one such reporter from the New York Times, who explained in a published story how she lost $50,000 to a vishing scam in February, is one of these people. A few weeks later, when fraudsters working in Portugal pretended to be both national and international law enforcement agencies, the author of this piece almost lost 5,000 euros to a sophisticated vishing operation. 

Ryu explains that the combination of social engineering and technology enables these modern vishing scams to exploit even individuals who are aware of the risks of vishing and how their operators function. 

"These groups utilize a blend of coercion and persuasion over the phone to deceive their victims effectively," he stated. "Moreover, malicious applications are designed to manipulate human psychology. These apps not only facilitate financial theft through remote control after installation but also exploit the call-forwarding feature.” 

This suggests that there are several vishing groups active throughout the world, emphasising the need to be cautious even when dealing with the most convincing schemes, according to Ryu. To prevent compromise, it's also essential to train staff members on the telltale signs of frauds and the strategies attackers typically implement to trick victims.