Filing text · FY2025 10-K · filed Aug 28, 2025Like other companies, we are subject to ongoing attempts by malicious actors, including through hacking, malware, ransomware, denial-of-service attacks, social engineering, exploitation of internet-connected devices, and other attacks, to obtain unauthorized access to, acquire or misuse confidential information, or to disrupt service reliability and threaten the confidentiality, integrity and availability of our systems and information we process. Cyber threats have increased in recent years, in part due to increased remote work and frequent attacks, including in the form of phishing emails, malware attachments and malicious websites. Additionally, cybersecurity researchers have warned of increased risks of cyber-attacks, in connection with the Russia-Ukraine war. While we work to safeguard our internal network systems and validate the security of our third-party service providers to mitigate these potential risks, including through information security policies, employee awareness and training, there is no assurance that such actions have been or will be sufficient to prevent cyber-attacks or security breaches or incidents. We have been in the past, and may be in the future, subject to social engineering and other cybersecurity attacks, and these attacks may become more prevalent with substantial portion of our workforce being distributed geographically, particularly given the increased remote access to our networks and systems as a result. Further, our third-party service providers may have been and may be in the future subject to such attacks or otherwise may suffer security breaches or incidents. In addition, actions by our employees, service providers, partners, contractors, or others, whether malicious or in error, could affect the security of our systems and information. Further, a breach or compromise of our [removed] information technology infrastructure or that of our third-party service providers could result in the misappropriation of intellectual property, business plans, trade secrets or other information. Additionally, while our security systems are designed to maintain the physical security of our facilities and information systems, accidental or willful security breaches or incidents or other unauthorized access by third parties to our facilities or our information systems could lead to unauthorized access to, or misappropriation, disclosure, or other processing of proprietary, confidential and other information.[removed] Moreover, new laws and regulations, such as the European Union's General Data Protection Regulation, the California Consumer Privacy Act ("CCPA"), add to the complexity of our compliance obligations and increase our compliance costs. Although we have established internal controls and procedures intended to comply with such laws and regulations, any actual or alleged failure to fully comply could result in significant penalties and other liabilities, harm to our reputation and market position, business and financial condition.
Filing text · FY2026 10-K · filed Aug 31, 2026Like other companies, we are subject to ongoing attempts by malicious actors, including through hacking, malware, ransomware, denial-of-service attacks, social engineering, exploitation of internet-connected devices, and other attacks, to obtain unauthorized access to, acquire or misuse confidential information, or to disrupt service reliability and threaten the confidentiality, integrity and availability of our systems and information we process. Cybersecurity threats may also be enhanced, accelerated or facilitated by artificial intelligence, including through more sophisticated phishing, malware, social engineering, vulnerability discovery, credential attacks, deepfakes, automated intrusion attempts and other techniques. The use of AI by malicious actors may increase the frequency, scale, speed and effectiveness of attacks against us, our suppliers, customers, service providers, partners and products, and may make such attacks more difficult to detect, investigate, contain or remediate. Cyber threats have increased in recent years, in part due to increased remote work and frequent attacks, including in the form of phishing emails, malware attachments and malicious websites. Additionally, cybersecurity researchers have warned of increased risks of cyber-attacks, in connection with the Russia-Ukraine war. While we work to safeguard our internal network systems and validate the security of our third-party service providers to mitigate these potential risks, including through information security policies, employee awareness and training, there is no assurance that such actions have been or will be sufficient to prevent cyber-attacks or security breaches or incidents. [added] We have been in the past, and may be in the future, subject to social engineering and other cybersecurity attacks, and these attacks may become more prevalent with substantial portion of our workforce being distributed geographically, particularly given the increased remote access to our networks and systems as a result. Further, our third-party service providers may have been and may be in the future subject to such attacks or otherwise may suffer security breaches or incidents, and if these third parties do not maintain adequate safeguards, a breach of their systems could in turn compromise our networks, products or customer data. Our systems may also be accessed by contractors, consultants, or other third-party vendors in connection with their services to us, and inconsistent screening, onboarding, or monitoring of such access could increase the risk of unauthorized access to our systems or data compromise. In addition, actions by our employees, service providers, partners, contractors, or others, whether malicious or in error, could affect the security of our systems and information. Further, a breach or compromise of our [added] IT infrastructure or that of our third-party service providers could result in the misappropriation of intellectual property, business plans, trade secrets or other information. Additionally, while our security systems are designed to maintain the physical security of our facilities and information systems, accidental or willful security breaches or incidents or other unauthorized access by third parties to our facilities or our information systems could lead to unauthorized access to, or misappropriation, disclosure, or other processing of proprietary, confidential and other information.[added]
Moreover, new laws and regulations, such as the European Union's General Data Protection Regulation, the California Consumer Privacy Act ("CCPA"), add to the complexity of our compliance obligations and increase our compliance costs. Although we have established internal controls and procedures intended to comply with such laws and regulations, any actual or alleged failure to fully comply could result in significant penalties and other liabilities, harm to our reputation and market position, business and financial condition.