Five Below disclosed a cybersecurity incident in an SEC Form 8-K after a threat actor used social engineering to gain unauthorized access to a company-issued employee computer and exfiltrate files from the device. The retailer said anomalous activity was identified the following day, prompting activation of its incident response plan, engagement of third-party cybersecurity and forensic specialists, and immediate containment measures.
The company said the intrusion was contained to the affected employee environment and that no other systems or platforms were impacted. Five Below also stated that no personally identifiable information was accessed or exfiltrated and that, based on its current assessment, the incident is not material to its business strategy, operations, financial condition, or results, while noting that conclusions could change if additional affected systems or harmful use of the stolen data is later identified.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
Five Below identified anomalous activity on the affected employee computer, activated its incident response plan, engaged third-party cybersecurity experts, and implemented containment measures. The company said the intrusion was limited to the employee environment with no other systems affected and no personally identifiable information accessed or exfiltrated.
Five Below said a threat actor used social engineering to gain unauthorized access to a company-issued computer used by an employee and exfiltrated a number of files from the device.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.