Five Below Reports Cybersecurity Incident Involving Social Engineering Attack

Five Below Reports Cybersecurity Incident Involving Social Engineering Attack

First seen 23 Jul 2026, 05:20 UTC StreetinsiderStocktitan 80% similarity 36.9

Article Content

Browse articles
ThreatCluster

On July 14, 2026, Five Below, Inc. experienced a cybersecurity incident where a threat actor used social engineering to gain unauthorized access to a company-issued computer. The company detected anomalous activity on July 15, 2026, and activated its cybersecurity incident response plan, engaging third-party experts for a forensic investigation. The investigation revealed that files were exfiltrated from the affected device, but the company believes the incident was contained to that single computer. Importantly, Five Below stated that no personally identifiable information or other systems were compromised. The company does not anticipate a material impact on its business operations or financial condition due to this incident.

Key Points: • Five Below reported a cybersecurity incident involving a single employee's computer. • The attack was executed via social engineering, leading to file exfiltration. • The company believes the incident is contained and has not affected other systems or data.

ThreatCluster AI

Timeline

2026-07-14
Unauthorized access detected
A threat actor used social engineering to access a company-issued computer and exfiltrate files.
Stocktitan
2026-07-15
Anomalous activity identified
Five Below detected unusual activity on the employee's computer and activated its incident response plan.
Streetinsider
2026-07-22
Incident disclosed in SEC filing
Five Below filed an 8-K report detailing the cybersecurity incident and its limited impact.
Stocktitan

Community

Browse all →