HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedFINANCIAL_ACCOUNTIDENTITY_BASICLowContained
Five Below, Inc.
bd_20f8dcca1d05eba6 · schema v1 · pii pii-v1
Full breach record for Five Below, Inc. →Five Below, Inc. disclosed a data breach affecting customers who entered payment card information on its website between November 13, 2018, and January 11, 2019. The incident involved unauthorized access to payment card data, including names, addresses, card numbers, expiration dates, and CVVs. Five Below engaged a computer security firm, enhanced website security, notified payment card networks, and offered one year of Experian IdentityWorks to affected individuals.
This filing is one of 2 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (1) · sorted by filing gap
- bd_32b7aed6d7d58403Montana State AGfiled 2019-02-14Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-144713
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Feb 14, 2019
- Raw hash
- 0c30b77de1d167ecbcd43a81bcdc080c3ceceb81a08d317a54387b1c97fc5733
Reporting entity
- Name
- Five Below, Inc.norm: five below
Victim entity
- Name
- Five Below, Inc.norm: five below
Incident
- Discovered
- Jan 11, 2019
- Materiality determined
- Feb 7, 2019
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- FINANCIAL_ACCOUNTIDENTITY_BASIC
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 5 weeks(34 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.