Three Phone Calls. Your Entire Company. The Vishing Wave Hitting 200+ Businesses Right Now.
Levi Strauss just disclosed an SEC breach caused by three social-engineered employees. They're one of 200+ companies targeted in the past five weeks by the same vishing operation. Here's what every business leader needs to know.
Last Friday, Levi Strauss filed an 8-K with the SEC. The disclosure was brief and matter-of-fact: an unauthorized third party had used social engineering to compromise three employees' company-issued computers, and "certain corporate information" had been stolen.
No ransomware. No software vulnerability. No zero-day exploit. Three phone calls.
Levi Strauss is a $6.3 billion company with a dedicated security team and 19,000 employees. If this can happen to them, it can happen to you.
And here's the part that should stop you cold: they weren't singled out. Google's threat intelligence team found that the same operation had built digital infrastructure targeting more than 200 companies in the past five weeks. Levi's is just the one that disclosed it.
What Actually Happened
The attack didn't involve cracking a firewall or exploiting a software bug. It involved calling employees, impersonating someone trustworthy — an IT helpdesk, an executive, a vendor — and convincing them to hand over access.
This technique is called vishing: voice phishing. And in 2026, it's been supercharged by AI. Voice cloning tools can now replicate a senior executive's voice convincingly enough to fool people who have worked with that person for years. Automated dialing systems let criminals run these attacks at scale, targeting dozens of employees simultaneously across dozens of companies.
The group behind this wave — tracked by Google's threat intelligence team as UNC6671 — has been systematically targeting U.S. financial institutions and major businesses throughout July and August. Their playbook: identify the right employees through LinkedIn and other open sources, spoof caller ID to make the call appear legitimate, create urgency ("your account is being compromised right now"), and walk the victim through actions that hand over access.
The entry point isn't your firewall. It's your employees.
Why This Pattern Keeps Working
This isn't new. We've seen the same social engineering playbook used against Medtronic (3.8 million patients), Abbott Laboratories, JLR, and dozens of other organizations in 2026 alone. The technique works because it exploits human psychology — specifically, the instinct to help and the fear of creating a problem by not complying.
An employee gets a call from someone claiming to be from IT, telling them their account shows suspicious access from an unknown location. The "IT tech" walks them through a series of steps that seem reasonable: resetting a password, approving an MFA prompt, installing a "security tool." By the end of the call, the attacker is inside.
No technical sophistication required. No software to exploit. Just a phone call and a plausible story.
When these attacks are AI-assisted — using real voice samples scraped from earnings calls, podcasts, or social media to clone an executive's voice — the barrier to belief drops even further.
The Business Leader's Reality Check
Here's what most business leaders miss about social engineering attacks: your investment in technical security tools may not matter at all if the human layer isn't protected.
You can have a next-generation firewall, endpoint detection on every device, and multi-factor authentication on every account. If one of your employees is convinced to approve an MFA prompt by someone claiming to be your IT team, the attacker is in — with fully authenticated access.
This is precisely what's happened across the string of vishing-driven breaches in 2026. The attackers aren't bypassing security tools. They're walking through the front door using access that your own employees handed them.
That's not a technology problem. It's a people and process problem. And it requires a different kind of response.
Three Questions Every Business Leader Should Ask This Week
First: Does your team know what a real IT request looks like — and what it doesn't?
Your IT team should never call an employee and ask them to approve an MFA push they didn't initiate. Your IT team should never ask for a password over the phone. Your IT team should never ask an employee to install software during an unscheduled call. If your employees don't know these rules, they're a target.
A social engineering awareness program isn't a one-time training video. It requires regular reinforcement, simulated attacks, and a culture where employees feel comfortable saying "let me call you back through the official number" without fear of slowing things down.
Second: What happens when an employee reports a suspicious call?
In most organizations, the answer is: not much. There's no clear reporting path, no central tracking of attempts, and no feedback loop. Employees who report suspicious calls should be thanked and their reports should be investigated — because a vishing attempt that fails is intelligence about who's targeting you and how.
Organizations in this wave of attacks likely had multiple employees targeted before one succeeded. Had those early contacts been reported and acted on, Levi Strauss might not be filing an 8-K right now.
Third: When credentials are compromised, how quickly can you respond?
In social engineering attacks, the question isn't just whether you get breached — it's how much damage happens before you contain it. Levi Strauss's statement emphasized that "rapid response efforts successfully contained and terminated the unauthorized access." That's meaningful.
Many organizations lack the visibility to detect that an employee's account is being used by an attacker, let alone respond within hours. If you don't have behavioral monitoring on your endpoints and identity systems — alerting on unusual logins, unusual data access, or unusual file movements — you're relying on luck to detect an intrusion before it becomes catastrophic.
What You Should Do Now
Vishing attacks succeed when they're unexpected. Your employees are not the problem — they're doing what humans do when faced with an authoritative, urgent request. The answer is preparation, not blame.
Review your IT verification procedures. Establish a call-back protocol: any employee who receives an unsolicited call requesting account changes should hang up and call the IT helpdesk back on a number they look up independently. This single procedure would have stopped many of this year's highest-profile breaches.
Run a simulated vishing exercise. Knowing about the threat in the abstract is different from experiencing a convincing attempt. Third-party social engineering assessments reveal gaps that no policy document will catch.
Verify your detection capabilities. When an employee's account starts accessing files or systems they haven't touched before, does anyone notice? If the answer is "eventually" or "maybe," you have a gap worth closing.
The attackers targeting 200+ companies in the past five weeks aren't running sophisticated technical operations. They're making phone calls. The question is whether your organization is ready when one of those calls reaches your team.
TrustPoint Cyber works with business leaders to assess and strengthen the human and technical layers of their security posture — because in 2026, the most dangerous attack vector isn't a software exploit. It's a convincing voice on the other end of a phone.
Ready to strengthen your security?
TrustPoint Cyber delivers Zero Trust architecture, incident response, managed security, and vCISO services — built for your business.