Five Below discloses limited cybersecurity incident involving social engineering attack
Five Below identified anomalous activity on a company-issued computer on July 15, 2026, and determined that on July 14, 2026, a threat actor used social engineering techniques to gain unauthorized access to an employee's device and exfiltrate files. The company activated its incident response plan, engaged third-party cybersecurity experts, and contained the unauthorized access. As of the filing date, the company states it believes no personally identifiable information was accessed or exfiltrated, the incident was limited to the affected employee's environment, and did not affect other systems or platforms.
- Anomalous activity identified on July 15, 2026 on a company-issued computer
- Unauthorized access via social engineering occurred on July 14, 2026
- Company determined that no personally identifiable information was accessed or exfiltrated
- Incident was limited to the affected employee's environment
- Third-party cybersecurity experts assisted with forensic investigation
- Company states the incident did not affect other systems, platforms, data, or environments
The disclosure confirms the company contained a social-engineering intrusion with limited scope and no theft of customer or employee personal data, reducing the likelihood of material operational, reputational, or regulatory fallout for Five Below.
Derived from 8-K filed 2026-07-22. Not investment advice. Figures are extracted from the filing; prose is AI-assisted. View the source filing on SEC.gov →