Open report — full analysis, no account required.
Sign up to generate reports and read filings that aren't on the open list.
Get notified when FIVE files again. Create a free account and we'll email you the moment its next filing is analyzed.
Get filing alertsFive Below discloses contained cybersecurity breach via social engineering
Filed July 22, 2026 · Period ending July 14, 2026 · ~1 min read
Key Changes
-
medium
Threat actor gained unauthorized access to one employee's computer on July 14, 2026, through social engineering and exfiltrated files from that device.
Item 8.01 verify on EDGAR → -
medium
Company states the incident was contained to the single employee's environment with no personally identifiable information compromised and no impact to other systems or data.
Item 8.01 verify on EDGAR → -
low
Five Below does not expect the incident to materially affect business strategy, operations, financial condition, or results of operations.
Item 8.01 verify on EDGAR →
Summary
Five Below disclosed a cybersecurity incident in which a threat actor used social engineering to gain unauthorized access to one employee's computer on July 14, 2026, and exfiltrated files. The company detected the anomalous activity the following day and immediately activated its incident response plan with third-party cybersecurity experts. According to the filing, the breach was successfully contained to the single affected computer, with no personally identifiable information accessed and no impact to other company systems, platforms, or data environments.
The company does not expect material impact to its business or financial results. For a discount retailer handling customer payment data across hundreds of stores, the stated containment to one employee's device and absence of PII compromise, if accurate, limits the incident's significance. The rapid detection and response—within 24 hours—suggests functional monitoring and incident protocols.
Section-by-Section Diff
Event · Item 8.01 — Other Events
Five Below disclosed a contained cybersecurity incident involving unauthorized access to one employee's computer via social engineering.
Added in current filing · verify on EDGAR →
On July 15, 2026, Five Below, Inc. (the “Company”) identified anomalous activity on a Company-issued computer belonging to an employee. Upon detection, the Company promptly activated its cybersecurity incident response plan, initiated a forensic investigation, with assistance from third-party cybersecurity experts, and took immediate steps to contain the activity.
Five Below detected unusual activity on an employee's computer on July 15, 2026, and immediately launched its incident response plan with third-party cybersecurity experts to investigate and contain the threat.
Thanks — your feedback helps us improve report quality.
Figures/quotes linked to EDGAR · Narrative written by AI · Jul 23, 2026 · How we verify