ITEM 1.05 MATERIAL CYBERSECURITY INCIDENTS
As disclosed in the Original Report, on May 6, 2024, the Company detected unauthorized third party access to portions of its information technology (“IT”) systems¹,²,³ (the “cybersecurity incident”). Upon detection of this outside threat, the Company activated its cyber incident response procedure to investigate, contain, and remediate the incident, including engaging external cybersecurity experts to help investigate the scope and impact of the cybersecurity incident and notifying law enforcement⁴. The cybersecurity incident caused disruptions, and limitation of access, to portions of the Company’s business applications supporting aspects of the Company’s operations and corporate functions, including financial and operating reporting systems.
As a precautionary measure, the Company halted domestic and Mexico operations for approximately two weeks during remediation efforts, but other international operations continued without disruption⁵. As of the date of this filing, the Company’s operations and corporate functions have been restored, and we believe that the unauthorized third party no longer has access to the Company’s IT systems⁶.
Since the date of the Original Report, the Company has determined that the threat actor accessed and exfiltrated limited data from the Company’s environment, which includes some personally identifiable information⁷,⁸. The Company is in the process of providing appropriate notifications to potentially affected parties and to regulatory agencies as required by applicable law.
The Company has also incurred, and may continue to incur, expenses related to the cybersecurity incident, including approximately $600,000 to date related to external cybersecurity experts⁹. The Company believes that the impact to profit margins due to lost production for approximately two weeks in its domestic and Mexico operations and the incremental expense measures to recover from and remediate the cybersecurity incident will have a material impact on the Company's financial condition and results of operations during the fourth quarter ending June 29, 2024¹⁰,¹¹.
Forward-Looking Statements. This Current Report contains forward-looking statements within the meaning of the Private Securities Litigation Reform Act of 1995. These statements address the Company’s expectations or beliefs regarding future events, actions or performance, including the investigation, containment and remediation of the cybersecurity incident and the impact on the Company, including its financial condition and results of operations. Factors that could affect future developments and performance include the completion of the Company’s investigation, the possibility that containment and remediation may not be successful, the improper use of exfiltrated information and related regulatory proceedings or litigation and other risks and factors contained in the documents that the Company has filed with the Securities and Exchange Commission.