Skip to main content

Brazilian Outlook

Levi’s Cybersecurity Breach Puts Apparel Industry Risks in Focus


Levi Strauss & Co. (LS&Co.) was the recent target of a cybersecurity incident.

On Aug. 7, LS&Co. reported a cybersecurity breach with the U.S. Securities and Exchange Commission after an unauthorized third party gained access to company files through social engineering techniques that enabled unauthorized access to three employees’ company-issued computers. The company said it believes corporate information was “accessed and exfiltrated” because of the incident.

More from WWD

Following the detection, LS&Co. said it initiated response protocols, implemented containment measures and launched an investigation, which remains ongoing. The company has also engaged the services of third-party cybersecurity experts.

While LS&Co. said it does not believe the incident will have any material impact on its operations, the breach highlights a wider issue of the hidden vulnerabilities brands face across a complex business ecosystem. And Levi’s is not alone. Adidas, The North Face, Nike, Victoria’s Secret, Gucci, Balenciaga and other major brands have also faced cybersecurity incidents in recent years.

With networks spanning numerous suppliers, manufacturers, logistics providers and other partners across multiple tiers and geographies, Joe Schloesser, senior vice president at ISN, a contractor and supplier information management firm, said brands need a clearer picture of who they’re doing business with and where potential risks may exist.

“Bad actors are increasingly exploiting trusted relationships to gain access to organizations, whether through employees, contractors, suppliers or other third parties,” he said. “Companies need strong processes for verifying who is requesting access and why, particularly when that access extends outside their own organization. In practice, that verification [must] extend to contractors and suppliers, where most immature programs stop.”

Training helps, but he said social engineering is designed to exploit human behavior, even among trained and careful employees. Schloesser explained how brands must use “organizational guardrails” like verification protocols, least-privilege access and monitoring so that one person’s mistake can’t cascade into full system compromise. He added that this third-party risk management approach is where ISN sees the widest maturity gap between brands and their contractors or suppliers.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *