Five Below Discloses Cyber Incident After Social Engineering Attack

Five Below disclosed that a threat actor used social engineering to access an employee computer and exfiltrate files before the intrusion was contained.
Five Below logo on a blue and purple abstract background.

Five Below has disclosed that a threat actor used social engineering to compromise an employee’s company-issued computer and exfiltrate files from the device.

The Philadelphia-based discount retailer revealed the incident in a Form 8-K filed with the U.S. Securities and Exchange Commission on July 22, 2026. Five Below said it currently believes the intrusion remained limited to the affected employee’s environment and did not expose personally identifiable information.

The company has not disclosed what files were stolen, how the employee was targeted, or how the social engineering attempt resulted in access to the computer.

Employee computer compromised

Five Below said the threat actor gained unauthorized access to the employee’s computer on July 14 using unspecified social engineering techniques.

The company detected anomalous activity on the device the following day and activated its cybersecurity incident response plan. Five Below then launched a forensic investigation with assistance from third-party cybersecurity experts and took steps to contain the activity.

According to the filing, the attacker exfiltrated “a number of files” from the compromised computer. Five Below did not identify the contents of those files or explain whether they contained internal business, operational, financial, or employee-related information.

The absence of personally identifiable information does not necessarily mean the stolen files lacked sensitivity. Corporate devices can contain internal communications, planning documents, reports, credentials, or other business information, although Five Below has not said that any of those data types were involved.

Five Below says access was contained

Five Below said its response efforts successfully terminated the unauthorized access and contained the incident to the employee’s environment.

Based on the investigation to date, the company said the attacker did not access or exfiltrate personally identifiable information and did not compromise its other systems, platforms, data, or environments.

The company also said it does not believe the incident has had, or is reasonably likely to have, a material effect on its business strategy, operations, financial condition, or financial results.

Five Below included the disclosure under Item 8.01 of the filing, which covers other events, rather than Item 1.05, the section companies use to report cybersecurity incidents they determine are material.

Social engineering remains a direct route into corporate systems

Social engineering attacks rely on manipulating employees into taking an action that gives an attacker access. That may involve deceptive calls, messages, fake support requests, malicious links, fraudulent login prompts, or attempts to persuade staff to install software or approve access.

Five Below did not provide enough technical detail to determine which method the attacker used in this incident.

The compromise highlights how a single employee endpoint can become an entry point for data theft even when an attacker does not gain broader access to corporate infrastructure. Rapid detection appears to have limited the scope in this case, according to the company’s current findings.

Retailer operates more than 1,900 stores

Five Below is a Philadelphia-headquartered discount retailer selling toys, technology accessories, candy, apparel, room décor, and other products. The company says it operates more than 1,900 stores across 46 U.S. states.

The retailer cautioned that its assessment could change if investigators identify additional affected systems or data. Its filing also acknowledged the possibility that the stolen information could be used in ways that harm the company’s competitive position or financial condition.

Five Below has not announced any customer or employee notification process because it currently believes no personally identifiable information was accessed or stolen.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site