Three employees, no exploit — what the Levi Strauss breach says about your human risk metrics

Three employees, no exploit — what the Levi Strauss breach says about your human risk metrics

On 7 August 2026, Levi Strauss & Co. filed an 8-K with the US Securities and Exchange Commission describing a cybersecurity incident. The description is short and worth reading closely: an unknown attacker social-engineered three of the company's employees, gained access to their company-issued computers, and exfiltrated certain corporate information. Levi's says its response contained the access, that no consumer data was affected, and that operations were not disrupted.

There is no vulnerability in that sentence. No unpatched appliance, no exposed service, no missing header. A company with 19,000 employees and $6.3 billion in annual revenue lost corporate data because three people were persuaded to help.

Some outlets, including Reuters, have connected the incident to a threat cluster Google tracks as UNC6671. Levi's has not confirmed any attribution, so treat that link as reported rather than established. The tradecraft is worth understanding regardless, because it is what an awareness programme now has to defend against.

What the current campaigns actually look like

Google Threat Intelligence Group and Mandiant published a report on UNC6671 on the same day, and their description of the method is specific.

The attackers call employees, posing as internal IT help desk staff running a mandatory, urgent security migration. They frequently call people on their personal mobile numbers, and spoof the organisation's real help desk number so the caller ID looks right. The victim is directed to a login portal sitting behind adversary-in-the-middle infrastructure, which captures the username, the password, the MFA approval and the live session token in real time. From there the attackers register their own MFA device — after removing the existing one — and run automated Python and PowerShell scripts to pull data out of Microsoft 365, Okta and connected SaaS applications.

Google's assessment of an earlier phase of the same activity is blunt: these compromises are not the result of a security vulnerability in vendor products or infrastructure. The economics explain the volume — Google tracked over $10.6 million in Bitcoin payments to wallets associated with the group between 7 January and 12 May 2026, with initial demands above $3 million and typical settlements around $750,000.

Why click rate stopped being an answer

Most awareness programmes report one number to the board: the phishing simulation click rate, trending down. It is a comfortable metric and it is nearly useless as a predictor of the attack above, for four reasons.

It measures one channel. The Levi's intrusion, and the campaigns it resembles, arrive by telephone — often on a device your organisation does not own and cannot instrument. An email click rate says nothing about how staff behave on a phone call.

It measures the wrong moment. Clicking a link is not the breach. Entering credentials, approving an MFA prompt, registering a new authenticator or allowing a remote session is the breach. Two organisations with identical click rates can be worlds apart on what happens in the ninety seconds afterwards.

It decays into theatre. People learn to spot simulation infrastructure rather than attacks. A falling click rate may mean staff are safer, or it may mean your templates have become recognisable. Nothing in the number distinguishes the two.

It is silent on what decides outcomes. Levi's disclosed three compromised employees, not zero. Someone always falls for it eventually. What determined the size of that incident was detection and response speed, and click rate measures neither.

What to measure instead

A human risk programme should be able to answer six questions with numbers. None of them is click rate.

How fast does the first person report it? Time from first delivery of a simulated attack to the first genuine report is the most operationally useful figure you have — it is what gives your security team a chance to act while the campaign is still running. Track the median and the tail.

What proportion of recipients report, versus merely not clicking? Silence is not a defence. Someone who deletes a suspicious message protects themselves; someone who reports it protects everyone. Report rate should be rising even as click rate flattens.

Do people verify through a known channel? This is the behaviour that actually defeats vishing. Bridewell documented a real attempted call in which the targeted employee tried to redirect the caller to the official service desk; the caller refused, insisted on an "alternate way" in, and hung up when the employee said he would gather more information first. That is the whole defence, in one interaction — and it is measurable. Run authorised callback drills and record what fraction of staff verify independently rather than complying.

How does your help desk perform when someone calls it? The reverse direction is a control too, and an under-tested one. Measure the failure rate of your identity-verification procedure during drills: how often an agent resets a password, re-enrols MFA or grants access on the basis of information an attacker could gather from LinkedIn. If your procedure accepts employee ID and manager's name, it has already failed.

What fraction of your workforce is covered on non-email channels? Count it explicitly: voice, SMS, personal-device contact, QR codes, MFA fatigue, adversary-in-the-middle portals. If 100% of your simulation programme is email, your coverage of the current threat is 0%. This is where a phishing simulation programme has to expand, and where most stop.

What is the blast radius of one compromised identity? This technical metric belongs in a human risk report, because it converts a mistake into an outcome. What percentage of accounts are on phishing-resistant MFA. Whether MFA registration and removal events raise an alert. Whether a single SSO session opens every connected SaaS application. A programme that cuts click rate by 5% while leaving one session able to reach everything has bought very little.

Where this connects to your obligations

For organisations in scope of NIS 2, awareness training is not optional and neither is management's own participation in it. A regulator asking about your programme will not be satisfied by a downward-trending click rate. Evidence of coverage, cadence, scenario realism and measured behaviour change is worth assembling now rather than during an inspection — the angle our audit and compliance work and the NIS 2 and DORA checklist both take.

This article is general information, not legal advice. Obligations depend on your sector, size and national implementing legislation.

The uncomfortable summary

Three employees is not a training failure. It is a normal outcome, and any programme built on the assumption that it can be driven to zero is measuring the wrong thing.

The realistic goal is different: make the attack harder to run, make it detectable in minutes rather than days, make the help desk an obstacle rather than an accomplice, and make sure a single stolen session does not open the whole building. That is what a human risk management programme is for, and every part of it is measurable — just not by the number most organisations currently report.

Sources: Levi Strauss & Co. Form 8-K, 7 August 2026; BleepingComputer, 7 August 2026; Google Threat Intelligence Group and Mandiant on UNC6671; The Hacker News, 7 August 2026; Bridewell on an attempted vishing call. Attribution of the Levi Strauss incident to UNC6671 is media-reported and has not been confirmed by the company.

Back to blog