Levi Strauss breach has expert analysis 

The Levi Strauss cyber incident is drawing attention after the company disclosed that attackers successfully used social engineering to compromise employee accounts.

Denis Calderone, CTO, Suzu Labs (https://www.linkedin.com/in/deniscalderone)

“The 8-K doesn’t name a threat actor and no group has claimed responsibility publicly. But the timing, the TTPs, social engineering targeting employee endpoints followed by corporate data exfiltration, and the fact that Reuters named Levi Strauss yesterday as a confirmed target of UNC6671’s vishing campaign make this a pretty short list of suspects. This group has hit over 200 companies in five weeks and collected over $10 million in Bitcoin since January.

“The 8-K says three employee computers were compromised and containment was successful. What it doesn’t address is what happens after endpoint access in this group’s playbook. GTIG’s analysis of UNC6671 shows that compromised endpoints are the entry point, not the objective. Once they have credentials and session tokens harvested live over the phone through adversary-in-the-middle phishing, the automated exfiltration targets M365, SharePoint, and Okta using scripted tools that pull data at volumes no human generates. Counting machines misses the point. The question is what cloud environments those three sets of credentials had access to.

“Levi’s statement that no consumer data was impacted is meant to reassure, but it misreads where the extortion leverage actually sits for this group. UNC6671 deliberately shifted toward organizations holding M&A data, litigation files, and investor records because that information commands higher ransom payments. A publicly traded Fortune 500 retailer doesn’t need to lose consumer PII for the stolen data to be damaging. Supplier contracts, pricing models, board communications, unreleased financial projections, any of that gives an extortion group leverage when the alternative is public disclosure on a leak site.

“If your organization is in that 200-company target list, or frankly in any sector UNC6671 has cycled through this year, the detection surface is well defined because the TTPs are so consistent. Require managed devices for SSO authentication, because these actors are directing employees to phishing sites on personal devices and harvesting credentials live over the phone. Build alerts around authentication from residential proxy IPs that don’t match employee baselines. And monitor your cloud audit logs for scripted data access, specifically python-requests and PowerShell user-agent strings pulling files from SharePoint or OneDrive at inhuman volumes. That’s your early warning that three compromised endpoints have become a full cloud exfiltration event.”

Kevin Surace, CEO, Token (https://www.linkedin.com/in/ksurace)

“The Levi Strauss incident is another example of attackers realizing that it is easier to hack the employee than hack the network. Based on the campaign targeting Levi and hundreds of other companies, the likely playbook is remarkably simple: call an employee, impersonate IT, create urgency around a security or passkey update, and convince that employee to help authenticate the attacker. The attacker does not break in. The employee is manipulated into opening the door.

“What makes this especially important is that attackers are already using passkeys as part of the con. We have now seen campaigns where someone pretending to be IT calls an employee and says, “We need to upgrade your account to passkeys.” The employee follows what appears to be a legitimate enrollment process, but behind the scenes the attacker is establishing access and can even register an attacker controlled passkey on the victim’s account. Passkeys did not fail cryptographically. The human enrollment process around them failed.

“That is the lesson security leaders need to understand. Passkeys make the credential itself dramatically harder to phish, but they do not magically make the person holding it impossible to manipulate. Attackers are simply moving upstream to enrollment, recovery, device registration and the help desk. They attack wherever human judgment can still change who is trusted.

“The answer is to remove that judgment from authentication. For valuable enterprise access, identity should be bound to dedicated hardware that requires the actual employee’s biometric before the credential can ever be exercised. The credential should be domain bound, device bound, physically present and unavailable through cloud synchronization or a weaker recovery mechanism.

“A fingerprint sensor on a dedicated authentication device is fundamentally different from asking a phone or laptop to tell the enterprise that a biometric happened. The authentication hardware itself verifies the employee and holds the cryptographic credential. No fingerprint match means no authentication. A social engineer cannot talk the device into making an exception.

“This is why hardware bound biometric assured identity is where enterprise authentication is quickly moving. The objective is no longer simply to prove that somebody possesses a credential. It is to cryptographically prove that the authorized human is physically present with the authorized credential at the moment access is requested.

“The uncomfortable truth from Levi Strauss is that security awareness training cannot solve this by itself. You cannot build a security architecture whose success depends on every employee correctly identifying every convincing phone call, fake website and urgent IT request forever. Attackers only have to fool one person once. Authentication has to be designed so that even when the employee is fooled, the attacker still cannot get in.

“We used to say attackers do not break in, they log in. The next evolution is even more concerning: attackers are convincing employees to provision the keys that let the attackers log in. Security leaders need to close that door now.”

Levi’s needs to come clean about what happened here so that we can all learn from it. Because if we don’t learn from it, it will repeat again and again.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading