DisclosureLens
FEDERALItem 8.01 · voluntarySocial EngineeringRetail & ConsumerRetailData ExfiltratedLowContained

Five Below, Inc.

bd_5dc595ab64fb59bc · schema v1 · pii pii-v1

Severity

Low

Discovered

Jul 15, 2026

Filed

Jul 22, 2026

To disclose

7 days

Affected

Not disclosed

Confidence

66%
Full breach record for Five Below, Inc.3 incidents on file

Five Below, Inc. disclosed on July 22, 2026 that on July 15, 2026 it identified anomalous activity on a Company-issued employee computer. The investigation determined that on July 14, 2026 a threat actor used social engineering techniques to gain unauthorized access to that computer and exfiltrated a number of files. The company believes the access was contained and terminated, that no personally identifiable information was accessed or exfiltrated, and that the impact is not material.

Incident timeline

undetected · 1 days
discovery → filing · 7 days

Jul 14, 2026

Begins

Jul 15, 2026

Discovered

Jul 22, 2026

Filed

vs. sector median

7 wks faster

Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.