Levi's Cybersecurity Breach Sheds Light on Industry Vulnerabilities
By Editor • August 25, 2026 • 2 min read
Levi Strauss & Co. recently reported a cybersecurity breach that underscores significant risks in the apparel sector. On August 7, the company disclosed to the U.S. Securities and Exchange Commission that unauthorized access had been gained to company files through social engineering tactics targeting three employee computers.
Following the breach, Levi's implemented immediate response protocols, engaged third-party cybersecurity experts, and initiated an ongoing investigation. Although the company claims there will be no material impact on its operations, this incident highlights critical vulnerabilities that many brands face in a complex business landscape.
Levi's is not an isolated case; high-profile brands like Adidas, Nike, and Gucci have also encountered cybersecurity threats. Joe Schloesser, a senior vice president at ISN, emphasizes the need for brands to understand their business relationships better, as third-party contractors and suppliers often present hidden risks. "Bad actors are increasingly exploiting trusted relationships to gain access to organizations," Schloesser noted, advocating for stronger verification processes that extend beyond the organization itself.
To mitigate these risks, Schloesser suggests implementing organizational safeguards, such as least-privilege access and continuous monitoring, to prevent a single mistake from compromising entire systems. He points out that smaller suppliers, lacking robust cybersecurity measures, can become vulnerable points of entry for cybercriminals targeting larger brands. "A cyberattack on a smaller supplier could open a backdoor into a much larger organization," he explained.
ISN offers solutions to enhance security by collecting and evaluating crucial information about contractors and suppliers, assessing them based on various industry standards. Schloesser stressed that while increasing transparency in supply chains is essential, the manner in which information is shared plays a critical role in risk management.
"When supplier information is collected once and shared on a need-to-know basis, brands can gain visibility into their risks," Schloesser said. He urges businesses to incorporate cybersecurity into broader supply chain discussions, framing it as a shared responsibility. The brands that maintain a clear view of their supply chain are better equipped to identify and address potential cybersecurity gaps.
Source: wwd.com
#apparel industry #cybersecurity #ISN #Levi Strauss #supply chain