FIVE BELOW, INC

Jul 2026 · Graded Verified · Retail and Consumer · Government record

Incident summary

FIVE BELOW, INCJul 2026
Not yet quantified
VVerified
Five Below traced the intrusion to a single employee's company laptop, reached not by an exploit but by a threat actor who talked the person into granting access, and files were exfiltrated before the anomaly was ever flagged. The company's comfort is the blast radius: one machine, no PII, nothing else touched, a tidy story about a perimeter that turned out to be one talked-past employee. Who took the files, and how many, the filing does not say.
Retail and Consumer
SEC 8-K, Item 8.01
Initial attack type phishing or social engineering confirmed · Impact data theft confirmed

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index