Five Below
Disclosed Jul 22, 20262 months agoConfirmed
Cybersecurity incident disclosed to the SEC (8-K Item 8.01)
The investigation determined that on July 14, 2026, a threat actor used social engineering techniques that enabled unauthorized access to that employee's Company-issued computer. The threat actor exfiltrated a number of files from the affected computer. As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, that the incident was limited to the affected employee's environment, that no personally identifiable information was accessed or exfiltrated, and that the incident did not affect the Company's other
What is known
| People affected | Not stated in the sources we have |
|---|---|
| Disclosed | Jul 22, 2026 |
| Attack | Phishing |
| Data exposed | Not stated |
| Sector | Other · US |
| Status | Confirmed |
Sources
| Source | |
|---|---|
| Five Below, Inc Form 8-K, Item 8.01 (2026-07-22)sec.gov · SEC filing | SEC filing |
Notices filed
| Where | Filed | People |
|---|---|---|
| SEC 8-K 8.01total | Jul 22 |
Other breaches at Five Below
| Breach | Affected | ||||
|---|---|---|---|---|---|
| Disclosed Oct 5, 2018Oct 5, 20187 years ago | Oct 5, 20187 years ago | Not stated | Other | Confirmed | 56K |
History of this record
- 2026-09-25 · added · backfill source
First seen 2026-09-25 (SEC 8-K 8.01), confirmed by SEC 8-K 8.01. Record counts are as reported. Not legal advice.