Five Below reports cybersecurity breach via social engineering
Five Below, Inc. (NASDAQ: FIVE) disclosed that a threat actor gained unauthorized access to a company-issued computer on July 14, 2026, using social engineering techniques.
The company said it identified the anomalous activity on July 15, 2026, and activated its cybersecurity incident response plan, retaining third-party cybersecurity experts to conduct a forensic investigation.
According to the filing, the threat actor exfiltrated a number of files from the affected computer. The company said it believes the incident was contained to a single employee's environment and that no personally identifiable information was accessed or exfiltrated. The company added that no other systems, platforms, data, or environments were affected.
Five Below said it does not believe the incident has had, or is reasonably likely to have, a material impact on its business strategy, operations, financial condition, or results of operations.
