Five Below, Inc.
ent_019e6283a9e6cfa2bca50cddf20d441a
Disclosures
8
SEC 8-K · State AG · 5 jurisdictions
Multi-filing incidents
2
incidents joining 2+ filings here
Max affected reported
1,707
as filed · State AG MA
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Five Below, Inc.
- Normalized
- five below— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 529900AAXP5Z6BGI7418
- SEC EDGAR CIK
- 0001177609
- Domain
- None on record
Disclosure history (8)newest first
- FEDERALSEC 8-Kas victim2026-07-22
Five Below, Inc. disclosed on July 22, 2026 that on July 15, 2026 it identified anomalous activity on a Company-issued employee computer. The investigation determined that on July 14, 2026 a threat actor used social engineering techniques to gain unauthorized access to that computer and exfiltrated a number of files. The company believes the access was contained and terminated, that no personally identifiable information was accessed or exfiltrated, and that the impact is not material.
- Massachusetts State AGas victim2019-02-15
Five Below, Inc. reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2019-02-15. 1,707 Massachusetts residents were affected. The report records the breach type as electronic.
- California State AGas victim2019-02-14
Five Below, Inc. reported unauthorized access to payment card data on its website between November 13, 2018, and January 11, 2019. The company detected suspicious activity on January 11, 2019. Affected data includes name, address, payment card number, expiration date, and CVV. The company engaged a security firm, enhanced website security, and offered one year of identity monitoring via Experian.
- Montana State AGas victim2019-02-14
Five Below, Inc. notified customers of a cybersecurity incident where unauthorized third-party access to its website checkout page potentially exposed payment card data (name, address, card number, CVV) for transactions between Nov 13, 2018 and Jan 11, 2019. The company engaged a security firm, enhanced website security, and offered one year of Experian IdentityWorks.
- New Hampshire State AGas victim2018-10-08
Five Below, Inc. notified the NH Attorney General of a security incident affecting 13 NH residents. Suspicious activity was observed on Aug 28, 2018, leading to the discovery of unauthorized access to payment card data (name, address, card number, CVV) for orders placed between Aug 14 and Sep 19, 2018. Notifications were mailed on Oct 5, 2018.
- Montana State AGas victim2018-10-05
Five Below, Inc. notified Montana residents of a cybersecurity incident where unauthorized third parties accessed customer order and payment card data (names, addresses, card numbers, CVVs) for orders placed between Aug 14–28 and Sep 18–19, 2018. The company engaged forensic investigators, enhanced website security, and offered one year of Experian IdentityWorks.
- Massachusetts State AGas victim2018-10-05
Five Below Inc reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2018-10-05. 97 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas reporting2018-10-05
Health Fitness Corporation disclosed a data breach where a software misconfiguration made health coaching records (consent forms, waivers, audio files) publicly accessible on the internet. Access began as early as August 2015. The misconfiguration was discovered on June 27, 2018. Affected data included names and employer information. The company engaged forensic investigators and provided 12 months of credit monitoring.