Breach taxonomy
Summary
Five Below identified anomalous activity on a company-issued employee computer on July 15, 2026. A threat actor used social engineering on July 14 to gain unauthorized access to that computer and exfiltrated a number of files. The company reports the incident was contained to the single employee environment, no personally identifiable information was accessed, and no other systems were affected. Filed under Item 8.01; company does not believe the incident is material.
Tagging rationale
ThreatUnknown
Filing refers only to 'a threat actor' with no attribution -> UNKNOWN.
MethodsData ExfilPhishing
Filing states 'a threat actor used social engineering techniques that enabled unauthorized access' and 'exfiltrated a number of files' -> DATA-EXFIL + PHISHING (social engineering vector).
AssetsConfidential Biz
Files were exfiltrated from a corporate employee computer; filing states no PII was accessed or exfiltrated -> CONFIDENTIAL-BIZ.
EffectsNetwork Security
Corporate files taken from one endpoint with no PII exposure, no operational disruption, and rapid containment -> NETWORK-SECURITY.
Impact
Incident limited to a single employee computer, no PII, no operational impact, contained same day -> score 1.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 8.01. Other Events. On July 15, 2026, Five Below, Inc. (the "Company") identified anomalous activity on a Company-issued computer belonging to an employee. Upon detection, the Company promptly activated its cybersecurity incident response plan, initiated a forensic investigation, with assistance from third-party cybersecurity experts, and took immediate steps to contain the activity. The investigation determined that on July 14, 2026, a threat actor used social engineering techniques that enabled unauthorized access to that employee's Company-issued computer. The threat actor exfiltrated a number of files from the affected computer. As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, that the incident was limited to the affected employee's environment, that no personally identifiable information was accessed or exfiltrated, and that the incident did not affect the Company's other systems, platforms, data, or environments. Based on information available as of the date of this filing, the Company does not believe the incident has had, or is reasonably likely to have, a material impact on the Company's business strategy, operations, financial condition, or results of operations.