Cyber attacks targeting major businesses continue to grow more sophisticated, with attackers increasingly relying on social engineering, compromised third-party services, and other methods to gain access to sensitive information. Recent incidents involving denim giant Levi Strauss and Valve’s Steam hardware products highlight the growing cybersecurity risks faced by global companies and their customers.
Levi Strauss Employees Targeted in Cyber Attack
Employees of popular denim retailer Levi Strauss have reportedly fallen victim to a social engineering-based cyber attack that resulted in the exposure of employee-related information and data connected to certain internal business operations.
The incident was disclosed by the company in its latest filing with the U.S. Securities and Exchange Commission (SEC). Levi Strauss, which operates globally and serves millions of customers, said the incident involved attackers targeting employees in an attempt to obtain credentials and authentication information.
According to details surrounding the incident, cyber criminals contacted three Levi Strauss employees and attempted to deceive them into providing login credentials and multifactor authentication (MFA) codes. By obtaining these details, the attackers were able to gain unauthorized access to systems and information.
The company’s incident response and cybersecurity teams moved quickly to contain the attack and limit further damage. Investigators are now working to determine the full extent of the compromise, while the company continues efforts to secure affected systems and address the consequences of the data exposure.
Google’s threat intelligence teams have reportedly tracked the attackers to a group identified as UNC6671. The group has also been linked to a threat actor believed to have backing from an adversarial entity, raising concerns about the increasing sophistication and potential motivations behind such cyber attacks.
The incident serves as another reminder that even organizations with strong cybersecurity defenses can be vulnerable when attackers successfully exploit employees through social engineering.
Valve Steam Hardware Data Exposed Through Logistics Partner
Valve, the company behind the popular Steam gaming platform and its hardware products, has also come under scrutiny following reports of a data breach involving customers who purchased Steam hardware in Europe.
According to posts appearing on Reddit, information belonging to European consumers who ordered Steam-related hardware was reportedly exposed online. The information allegedly includes customer names, physical addresses, telephone numbers, email addresses, details of products purchased, and the prices paid.
Valve subsequently confirmed that it was investigating the incident. The company said the breach was connected not directly to its core Steam systems, but to CEVA Logistics, a third-party logistics provider responsible for shipping products such as Steam Deck hardware, controllers and other Steam-related devices.
According to the information released by Valve, the security incident potentially provided unauthorized individuals with access to customer information between July 29 and August 1, 2026.
The incident highlights the cybersecurity risks associated with third-party vendors and supply-chain partners. Even when a company’s own systems remain secure, attackers can potentially target service providers that have access to customer or operational data.
Both incidents demonstrate how cyber criminals are increasingly exploiting human behavior and trusted business relationships rather than relying solely on traditional technical vulnerabilities.
Companies across industries are therefore being forced to strengthen employee awareness, multifactor authentication protections, vendor security controls and incident-response capabilities to reduce the impact of increasingly sophisticated cyber attacks.
