07/22/2026 | Press release | Distributed by Public on 07/22/2026 15:20
| Item 8.01. |
Other Events. |
On July 15, 2026, Five Below, Inc. (the "Company") identified anomalous activity on a Company-issued computer belonging to an employee. Upon detection, the Company promptly activated its cybersecurity incident response plan, initiated a forensic investigation, with assistance from third-party cybersecurity experts, and took immediate steps to contain the activity.
The investigation determined that on July 14, 2026, a threat actor used social engineering techniques that enabled unauthorized access to that employee's Company-issued computer. The threat actor exfiltrated a number of files from the affected computer.
As of the date of this filing, the Company believes that its rapid response efforts successfully contained and terminated the unauthorized access, that the incident was limited to the affected employee's environment, that no personally identifiable information was accessed or exfiltrated, and that the incident did not affect the Company's other systems, platforms, data, or environments.
Based on information available as of the date of this filing, the Company does not believe the incident has had, or is reasonably likely to have, a material impact on the Company's business strategy, operations, financial condition, or results of operations.
Certain statements contained in this Current Report on Form 8-K constitute forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995, including, without limitation, statements regarding the scope, impact, and anticipated consequences of the cybersecurity incident described herein. These forward-looking statements are based on the Company's current expectations, estimates, and assumptions and are subject to risks and uncertainties that could cause actual results to differ materially, including the risks that the Company may identify additional affected systems or data, that the exfiltrated information may be used in ways harmful to the Company's competitive position or financial condition, that regulatory authorities may reach conclusions different from those of the Company, or that litigation may result from the incident. The Company undertakes no obligation to update or revise any forward-looking statements, whether as a result of new information, future events, or otherwise, except as required by law.