Breach taxonomy
Summary
Five Below identified anomalous activity on a company-issued employee computer on July 15, 2026. A threat actor used social engineering on July 14 to gain unauthorized access to that computer and exfiltrated a number of files. The company reports the incident was contained to the single employee environment, no personally identifiable information was accessed, and no other systems were affected. Filed under Item 8.01; company does not believe the incident is material.
Tagging rationale
ThreatUnknown
Filing refers only to 'a threat actor' with no attribution -> UNKNOWN.
MethodsData ExfilPhishing
Filing states 'a threat actor used social engineering techniques that enabled unauthorized access' and 'exfiltrated a number of files' -> DATA-EXFIL + PHISHING (social engineering vector).