Item 8.01 | Other Events. |
On February 14, 2025, NioCorp Developments Ltd. (the “Company”) became aware of unauthorized third-party access to its information systems, including portions of its email systems, that resulted in misdirected vendor payments totaling approximately $0.5 million¹,²,³,⁴ (the “cybersecurity incident”). The Company self-discovered the cybersecurity incident and promptly notified certain financial institutions and federal law enforcement in an effort to, among other matters, recover the misdirected vendor payments. In addition, upon discovery of the cybersecurity incident, the Company began taking steps to investigate, contain, assess and remediate the cybersecurity incident.⁵
Although the Company believes that the cybersecurity incident is limited to the misdirected vendor payments, the Company’s investigation of the cybersecurity incident remains ongoing and the full scope, nature and impact of the cybersecurity incident are not yet known⁶. As of the date of this filing, the Company has not yet determined whether the cybersecurity incident is reasonably likely to materially impact the Company’s overall financial condition or its results of operations, including whether the Company will ultimately be able to recover all or a portion of the misdirected vendor payments.⁷,⁸
**Note Regarding Forward-Looking Statements**
This Current Report on Form 8-K contains forward-looking statements within the meaning of the United States Private Securities Litigation Reform Act of 1995 and forward-looking information within the meaning of applicable Canadian securities laws. These forward-looking statements, include, but are not limited to, statements regarding the Company’s current beliefs, understanding and expectations regarding the cybersecurity incident and its scope, nature and impact on the Company’s business, operations and financial results. Factors that could cause actual results to differ from those expressed in these forward-looking statements include the outcome of the Company’s ongoing assessment of the cybersecurity incident and its ability to remediate the impact of the cybersecurity incident; legal, regulatory, reputational and financial risks resulting from the cybersecurity incident or additional cybersecurity incidents; and the risks described in the Company’s Annual Report on Form 10-K for the year ended June 30, 2024 and subsequent Quarterly Reports on Form 10-Q. Unless required by law, the Company expressly disclaims any obligation to update publicly any forward-looking statements, whether as result of new information, future events or otherwise.