Five Below filed a Form 8-K with the Securities and Exchange Commission on July 22, 2026, disclosing a cybersecurity incident that occurred earlier in the month. The discount retailer, which operates nearly 2,000 stores across 46 states, stated that it identified anomalous activity on a company-issued computer belonging to an employee on July 15.
Upon detection, the company activated its cybersecurity incident response plan and launched a forensic investigation with the help of third-party cybersecurity experts. The investigation determined that on July 14, a threat actor used social engineering techniques to gain unauthorized access to that specific employee's computer. Social engineering typically involves manipulating individuals into divulging confidential information or granting access, often through phishing or impersonation, rather than exploiting a technical vulnerability in a system.
The threat actor exfiltrated a number of files from the affected computer. However, Five Below stated that its rapid response efforts successfully contained and terminated the unauthorized access. The company believes the incident was limited to the affected employee's environment and did not spread to other systems, platforms, data, or environments.
Critically for a retailer that handles customer transactions, Five Below reported that, based on its investigation to date, no personally identifiable information was accessed or exfiltrated. The company also stated that it does not believe the incident has had, or is reasonably likely to have, a material impact on its business strategy, operations, financial condition, or results of operations.
The filing includes forward-looking statement disclaimers that acknowledge risks and uncertainties. These include the possibility that the company may later identify additional affected systems or data, that the exfiltrated information could be used in ways harmful to Five Below's competitive position or financial condition, that regulatory authorities might reach different conclusions, or that litigation could arise from the incident.
The disclosure comes during a period of strong financial performance for Five Below. The company most recently reported first quarter fiscal 2026 net sales of $1.3 billion, a 32.5% increase year-over-year, and raised its full-year outlook. The contained nature of this incident, as currently understood, appears unlikely to disrupt that trajectory, though the standard caveats in the filing remind investors that cybersecurity investigations can evolve as forensic analysis continues.