TL;DR

Levi Strauss confirmed that social engineering of just three employees was enough to steal corporate data (BleepingComputer, 2026-08). Meanwhile, device-code phishing surged 1,500% and vishing doubled in 2026 (Dark Reading, 2026-08), and ASD ACSC released dedicated training modules for privileged ICT users (cyber.gov.au, 2026-08). The takeaway for governance: annual phishing simulations and pass-rate dashboards no longer evidence that your organisation can withstand modern social engineering. The four-pillar evidence matrix below maps each active vector to the specific training record, payment-verification control, policy decision, and accountability artifact your business can stage immediately.

What changed

Three developments in August 2026 collectively reshape what evidence is needed:

  1. Levi Strauss breach confirms low-employee-count social engineering is sufficient for data theft. BleepingComputer reports that hackers used social engineering on three Levi's employees to gain access to and steal corporate data stored on their machines. lilMONSTER's interpretation: if an attacker needs only three staff members, the relevant governance question is not "how many employees clicked the simulation?" but "can three targeted individuals make a decision that bypasses all technical and financial controls?" This shifts the evidence burden from aggregate awareness metrics to decision-point controls and their audit trails.

  2. Device-code phishing surged 1,500% in 2026, and vishing doubled. Dark Reading reports that newer social-engineering techniques allow attackers to bypass entrenched security controls and limit the forensic evidence they leave behind. lilMONSTER's interpretation: when the attack vector is a trusted device-code flow or a phone call, email-security dashboards are blind to it. Governance evidence must therefore cover out-of-band channels, not just email.

  3. ASD ACSC published dedicated training for privileged ICT users. The Australian Signals Directorate released short video modules specifically for privileged users, acknowledging that this group faces different and higher social-engineering risk than the general workforce. lilMONSTER's interpretation: a government authority has formally separated privileged-user training from general awareness training. Businesses that present undifferentiated training records to insurers or boards are now behind the authoritative baseline.

Why it matters for business trust

Each development changes a specific business decision:

  • Insurer renewal: Underwriters increasingly ask whether privileged users receive targeted training and whether payment-verification controls cover social-engineering-initiated transactions. The Levi's breach confirms the loss model. Without evidence that privileged-user training exists (per the ASD ACSC model) and that payment redirection attempts are independently verified, expect higher premiums or coverage exclusions.

  • Board reporting: A board that receives only phishing-simulation click rates cannot discharge its oversight duty when the active vectors are device-code phishing and vishing. The Dark Reading data means the board's risk picture is incomplete unless the report covers non-email social-engineering channels.

  • Tender and customer due diligence: Enterprise customers now ask whether supplier staff who handle their data have been trained against the current threat landscape, not a generic one. Citing the ASD ACSC privileged-user training as a benchmark strengthens supplier-assurance responses.

  • Executive accountability: If three employees can trigger a breach, accountability must be traceable. Who approved the access those employees held? Who reviewed the payment-verification policy? Who signed off on the training scope? Evidence of named accountability is now the differentiator between a defensible posture and an exposed one.

Evidence to produce now

lilMONSTER Social-Engineering Governance Evidence Matrix

Map each active threat vector to four governance pillars. For each cell, identify whether the artifact exists, is current (within 90 days), and is attributable to a named owner.

Threat Vector (Source) Training Evidence Payment Verification Evidence Policy Decision Evidence Executive Accountability Evidence
Targeted employee social engineering (Levi's breach — BleepingComputer) Role-based training records for staff with data or system access; separate from general phishing simulation Payment-redirection-response procedure with dual-authority sign-off for any change initiated by a non-finance employee Access-approval policy defining who can grant elevated access and under what delegated authority Named owner (CISO or equivalent) with quarterly attestation that role-based training completion was reviewed
Device-code phishing (+1,500% in 2026 — Dark Reading) Module or briefing covering device-code flow abuse, delivered to all identity-privileged users Out-of-band verification requirement for any authentication prompt received via email, chat, or phone Conditional-access policy restricting device-code flow where feasible; documented exception list with expiry dates Security-operations lead attestation that device-code logs are reviewed; risk-acceptance record signed by a named executive for any exception
Vishing / callback fraud (doubled in 2026 — Dark Reading) Vishing-specific scenario training including caller-ID spoofing and authority-impersonation response Mandatory callback to a pre-registered number for any payment instruction or credential reset received by phone Incident-response playbook entry for reported vishing attempts, with escalation criteria to finance and IT Quarterly review of vishing reports by a governance committee with minutes recording decisions
Privileged-user targeting (ASD ACSC training series — cyber.gov.au) Privileged-user-specific training, benchmarked against ASD ACSC modules; completion recorded per individual, not aggregate Privileged-action payment or system-change verification independent of the privileged user's own authority Privileged-access management policy with named approvers, periodic recertification, and revocation triggers Named executive (CIO or delegate) accountable for the privileged-access register, with annual sign-off

30-Minute Review Procedure

0-10 min: Pull the last 90 days of training records. Identify whether privileged users have a separate curriculum from general staff. If not, this is finding one.

10-20 min: Retrieve the payment-verification policy. Confirm it covers non-finance-initiated changes, phone-initiated instructions, and device-code authentication prompts. If any gap exists, this is finding two.

20-25 min: Locate the conditional-access or identity policy. Check for device-code-flow restrictions and a named exception list. If absent, this is finding three.

25-30 min: Identify the named executive accountable for each of the four pillars above. If any pillar has no named owner, this is finding four.

FAQ

Q: Our phishing-simulation click rate is below 5%. Does that satisfy governance evidence?

No. The Levi's breach demonstrates that targeted social engineering on a small number of employees is sufficient to steal data, and device-code phishing bypasses email entirely. Click rates evidence email-click behaviour, not decision-making under targeted pressure. Insurers and boards increasingly expect evidence of privileged-user training, payment verification, and named accountability alongside simulation data.

Q: We are not an Australian organisation. Does the ASD ACSC training benchmark apply?

The ASD ACSC modules represent a government authority's formal recognition that privileged users require distinct training. While the modules are published by an Australian agency, the principle (role-differentiated training for privileged users) is broadly applicable. Referencing it as a benchmark in supplier-assurance or insurer responses demonstrates alignment with an authoritative source, regardless of jurisdiction.

Q: What is device-code phishing, and why does it matter for payment verification?

Device-code phishing exploits a legitimate authentication flow where a user enters a code displayed on one device into a web form on another. An attacker tricks the user into entering the code into the attacker's session, granting access without a password. Dark Reading reports a 1,500% increase in 2026. For payment verification, this means an attacker could authenticate as a legitimate user and initiate or approve a transaction through a trusted channel, making out-of-band verification essential.

Q: How often should the evidence matrix be reviewed?

lilMONSTER recommends a 90-day review cycle, aligned with the review_cycle_days field in this brief. Social-engineering techniques are evolving rapidly, as the device-code phishing and vishing data demonstrates. A quarterly review ensures the matrix reflects current vectors and that named owners confirm their artifacts remain current.

Conclusion

The distance between a strong phishing-simulation dashboard and actual social-engineering resilience is where governance evidence lives. The Levi's breach, the device-code phishing surge, and the ASD ACSC privileged-user training each confirm a different facet of that gap. Use the evidence matrix above to identify which artifacts exist, which are current, and which pillars have no named owner. If any cell is empty, that is your next governance decision.

For help building the full evidence package for your next insurer renewal, board briefing, or tender response, book a consultation at https://consult.lil.business/.

References

  1. Levi Strauss & Co. says hackers stole corporate data in cyberattack — BleepingComputer
  2. Device Code Phishing Up 1,500% in 2026; Vishing Doubles — Dark Reading
  3. New video series supports cyber security training for privileged users — ASD ACSC

TL;DR

  • The President made a new plan to catch cybercriminals who hurt families and businesses
  • Last year, people lost $12.5 billion to online scams—that's like 500,000 new cars!
  • The government will now work together to catch bad guys and help get money back
  • You still need to lock your digital doors with passwords and safety tools

What Is an Executive Order?

Think of an Executive Order like when your parents make a new rule for the whole family. But instead of a house, it's for the entire country. The President signed a special paper that tells all the police and helpers to work together to stop online bad guys [1].

It's like when your teacher makes a plan for the whole class to work together on a big project. Everyone has a job to do.

Why Did the President Do This?

Imagine if someone kept breaking into houses in your neighborhood, but nobody worked together to catch them. That's what was happening with online crime.

Last year, people in America lost $12.5 billion—that's billions with a B! [1]. That's enough money to buy 500,000 new cars. Or build 250 new elementary schools. Or buy everyone in a big city a brand new bicycle.

The bad guys were:

  • Tricking people into sending money
  • Locking up business computers and demanding payment
  • Pretending to be someone they're not
  • Scaring grandmas and grandpas

And they were doing it from other countries where American police couldn't catch them.

What's New That Helps Your Family

A Special Team to Catch Bad Guys

The President created a special team called the National Coordination Center (NCC) [1]. Think of them like the Avengers, but for catching online criminals. Instead of Iron Man and Captain America, it's FBI agents, police, and computer experts all working together.

Getting Your Money Back

Here's something really cool: the President wants to make a program called the Victims Restoration Program [1]. If you get tricked into sending money to a bad guy, and the police catch them and get the money back, this program would give it back to you.

It's like when you lose your lunch money, someone finds it, and they make sure it gets returned to you.

Teaching Police How to Help

The plan also helps police everywhere learn how to stop online bad guys [1]. It's like giving everyone in your class the same textbook and training so everyone knows how to solve the problems.

Telling Other Countries to Stop Bad Guys

Some countries let bad guys live there and do crimes from their computers. The President's plan says "Hey, you need to stop these people or we won't be friends anymore" [1]. It's like telling your neighbor they need to stop their dog from digging in your yard.

This Doesn't Mean You Can Stop Being Careful

Even with this new plan, you still need to be safe online. Think about it like this: The police are working hard to stop burglars, but you still lock your front door, right?

Keep Your Digital Doors Locked

  • Use strong passwords that are hard to guess—like a sentence instead of just one word
  • Use two-factor authentication (that's when you need both a password and a code from your phone)
  • Don't click on weird links in emails, even if they look real
  • Tell an adult right away if something seems wrong or scary online

Tell Your Parents About This Stuff

If your family has a business, talk to your parents about:

  • Making sure the business has good security on its computers
  • Backing up important files (making extra copies in a safe place)
  • Being careful with emails that ask for money or passwords
  • Knowing who to call if something bad happens

What Happens Next?

Right Now (The Next Few Weeks)

The government starts making plans. They figure out who needs to do what job, like a coach assigning positions to a sports team.

Soon (In a Few Months)

The special teams start working together. They begin catching bad guys and stopping scams. The training programs for police start up.

Later (In 6 to 12 Months)

The program to help people get their money back might start working. More bad guys get caught. There should be fewer scams because the police are working better together.

What You Can Do Today

For Your Family

  • Talk about being safe online together
  • Make a plan for what to do if someone tries to trick you
  • Keep passwords and codes secret—don't even share with best friends
  • If someone scary contacts you online, tell a grownup immediately

For Your Family Business

  • Ask your parents if the business has good computer security
  • Suggest they work with a security company like lilMONSTER to check if everything is safe
  • Make sure important files are backed up in case something goes wrong
  • Know how to report problems to the police and FBI

A Story About Why This Matters

Imagine you have a lemonade stand. You work hard making lemonade, setting up your table, and being nice to customers. Then one day, someone comes along, says they're collecting money for you, takes all your cash, and disappears.

That's what cybercriminals do to businesses every day. They pretend to be someone else, trick people into sending money, and steal what families worked hard to build.

The President's new plan is like having a neighborhood watch for the whole internet. People looking out for each other, working together, and making it harder for bad guys to get away with stealing.

The Big Lesson

The government is working hard to catch cybercriminals, but you still need to do your part. It's like wearing a seatbelt even though there are traffic laws and police to keep roads safe.

Bad guys exist online. They want to trick you and take your money. But now there are more people working to stop them than ever before.

Be smart. Be careful. And ask for help when you need it.

That's how you keep your family and your family business safe.

FAQ

No, just like how police can't catch every burglar in the real world. But they'll catch more than before, and work together better. You still need to be careful and protect yourself.

Tell a grownup right away. They should call the police and report it to the FBI at their website called IC3. The new program might help get money back if they catch the bad guy.

Some bad guys live in other countries where American police can't go. That's why the President is talking to other countries and telling them to stop letting bad guys hide there.

You don't need to worry, but you do need to be careful. It's like looking both ways before crossing the street. You don't have to be scared, but you do have to pay attention and follow the safety rules.

That's okay! You can help them by reminding them about safety rules, and your family can work with a company like lilMONSTER that knows how to keep businesses safe online.

References

[1] The White House, "Fact Sheet: President Donald J. Trump Combats Cybercrime, Fraud, and Predatory Schemes Against American Citizens," The White House, March 6, 2026. [Online]. Available: https://www.whitehouse.gov/fact-sheets/2026/03/fact-sheet-president-donald-j-trump-combats-cybercrime-fraud-and-predatory-schemes-against-american-citizens/

[2] National Crime Prevention Council, "Cybercrime Prevention Tips," NCPC, 2025. [Online]. Available: https://www.ncpc.org/resources/cybercrime-prevention

[3] Stop.Think.Connect, "Online Safety Tips for Families," DHS, 2025. [Online]. Available: https://www.stopthinkconnect.org

[4] National Cybersecurity Alliance, "Safe Online Surfing for Kids," NCSA, 2025. [Online]. Available: https://staysafeonline.org/kids

[5] FBI Safe Online Surfing, "Internet Safety," FBI, 2025. [Online]. Available: https://www.fbi.gov/sos

[6] Netsmartz, "Internet Safety for Kids," NCMEC, 2025. [Online]. Available: https://www.missingkids.org/netsmartz/home

[7] Common Sense Media, "Digital Citizenship and Safety," CSM, 2025. [Online]. Available: https://www.commonsensemedia.org/educators/digital-citizenship

[8] Cyber Safe Kids, "Online Safety Resources," CSK, 2025. [Online]. Available: https://www.cybersafekids.com


Keeping your family business safe online is a team effort. The government is doing their part, but you need to do yours too. Work with lilMONSTER to make sure your digital doors are locked tight. Talk to us about keeping your business safe