Business Context and Reporting Period
Company: FIVE BELOW, INC.
Filing Type: Form 8-K (Current Report)
Date of Report: July 14, 2026 (Event Date)
Subject: Item 8.01 Other Events - Cybersecurity Incident
Key Financial Metrics
The filing text does not provide a clear value for revenue, profit, cash flow, margins, debt, or liquidity. This report focuses exclusively on a specific operational event rather than periodic financial results.
Material Changes and Incident Details
- Incident Date: July 14, 2026.
- Event: Anomalous activity detected on a Company-issued computer belonging to an employee.
- Method: Threat actor utilized social engineering techniques to gain unauthorized access.
- Impact: Files were exfiltrated from the affected computer.
- Containment: The Company activated its incident response plan, engaged third-party experts, and successfully contained and terminated the unauthorized access.
- Scope: The incident was limited to the affected employee's environment. No other systems, platforms, or data were affected.
- Data Privacy: No personally identifiable information (PII) was accessed or exfiltrated.
Outlook, Risks, and Management Commentary
Management Assessment: The Company does not believe the incident has had, or is reasonably likely to have, a material impact on its business strategy, operations, financial condition, or results of operations.
Risks and Contingencies:
- Forward-looking statements regarding the incident are subject to risks and uncertainties.
- Potential identification of additional affected systems or data.
- Risk that exfiltrated information could be used to harm the Company's competitive position or financial condition.
- Possibility of regulatory conclusions differing from the Company's assessment.
- Potential for litigation resulting from the incident.
Investor Verification Checklist
- Confirm the final scope of the forensic investigation to ensure no additional systems were compromised.
- Monitor for any future announcements regarding regulatory inquiries or litigation related to the incident.
- Verify that the Company's assessment of "no material impact" remains valid as the investigation concludes.
- Review subsequent filings for any updates on the nature of the exfiltrated files.