Skip to content

Five Below

Disclosed Jul 22, 20262 months agoConfirmed

SEC filing

Cybersecurity incident disclosed to the SEC (8-K Item 8.01)

The investigation determined that on July 14, 2026, a threat actor used social engineering techniques that enabled unauthorized access to that employee's Company-issued computer. The threat actor exfiltrated a number of files from the affected computer. As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, that the incident was limited to the affected employee's environment, that no personally identifiable information was accessed or exfiltrated, and that the incident did not affect the Company's other

What is known

People affectedNot stated in the sources we have
DisclosedJul 22, 2026
AttackPhishing
Data exposedNot stated
SectorOther · US
StatusConfirmed

Sources

Source
Five Below, Inc Form 8-K, Item 8.01 (2026-07-22)sec.gov · SEC filing

Notices filed

WhereFiledPeople
SEC 8-K 8.01totalJul 22

Other breaches at Five Below

BreachAffected
Disclosed Oct 5, 2018Oct 5, 20187 years ago56K
History of this record
  • 2026-09-25 · added · backfill source

First seen 2026-09-25 (SEC 8-K 8.01), confirmed by SEC 8-K 8.01. Record counts are as reported. Not legal advice.

Everything about Five Below

New breaches by email

Wednesdays, only in weeks with newly disclosed breaches, the largest first.

Double opt-in. Unsubscribe any time.