Levi’s Hacked by a Phone Call, a City Beats Ransomware, and LockBit Is Back
A six-billion-dollar brand got breached this week, and the attackers never wrote a line of code. They called three employees and pretended to be IT. Every business owner should sit with this: the same phone call works even better on a company your size. *Every breach is won or lost before it begins.* Bryan Hornung, Randy Bryan, and Reginald Andre break down this week’s stories for executives, owners, and operators who do not have time to keep up with cyber news but cannot afford to be blindsided. The good news first. The City of Coweta, Oklahoma, a town of about ten thousand people, got hit with a ransomware attack that locked up every computer in City Hall. Permits, transactions, and in-person card payments stopped cold. But 911 never went down because police and fire systems run on separate off-site servers the attack could not reach. Coweta is refusing to pay the ransom for one reason: its backups actually work. That is the whole lesson in one town. Levi Strauss told the SEC that attackers stole corporate data after socially engineering just three employees. No malware. No exploit. Someone called pretending to be the internal help desk, led employees to a fake login page, and captured their passwords and live sessions in real time. Then they registered their own login devices, removed the real ones, and deleted security alerts so nobody got a warning. Google’s threat team says the crew behind this style of attack built tools to hit more than two hundred companies in about five weeks. If they will call Levi’s, they will call your front desk. LockBit is back. Law enforcement broke up the ransomware crew in 2024, but its 5.0 version has already listed more than two hundred victims. The latest is Microphase, a Connecticut company that has made radio and radar parts for the defense world since 1955. This is double extortion: they steal your data first, then threaten to publish it unless you pay. Backups alone will not save you. If they will hit a specialty parts shop, “we’re too small to be a target” is not a plan. Three stories, one thread. Coweta survived because of decisions made long before the attack. Levi’s got hurt in a single moment of misplaced trust. LockBit proves attackers are coming whether you are a household name or a shop nobody has heard of. The outcome was decided long before the attack. In this episode, we discuss: • How the City of Coweta kept 911 online while ransomware locked up City Hall • Why refusing to pay a ransom only works when your backups actually do • How attackers breached Levi Strauss with three phone calls and no malware • Why regular text-message MFA did not stop the Levi’s attackers, and what does • LockBit’s return and why a 1955 defense parts maker landed on its leak site • Why “we’re too small to be a target” is the most expensive assumption in business • The one habit that shuts down the fake-IT phone call for free Security Squawk is a weekly podcast and live stream for business owners and executives. Support the show: buymeacoffee.com/securitysquawk Subscribe | Like | Share #SecuritySquawk #CyberSecurity #Ransomware #DataBreach #LeviStrauss #LockBit #SocialEngineering #Vishing #SmallBusiness #BusinessRisk #MSP #Backups