Item 8.01. Other Events.
As disclosed in the Original Report, as further amended by Amendment No. 1, the Company identified a cybersecurity incident, which it has contained¹,²,³. Our engagement with law enforcement and regulators continues. Based on our investigation and findings, we will be notifying up to approximately 16.9 million individuals whose sensitive personal information was impacted by this cybersecurity incident⁴,⁵ as required by law, and, as previously disclosed, will offer those individuals credit monitoring and identity protection services at no cost to them⁶.
In addition, based on the information available to date, the Company believes that the cybersecurity incident will have a material impact on its first quarter 2024 results but does not expect the incident to have a material impact on full year 2024 results⁷,⁸. Specifically, among other things, the Company expects to record in the first quarter of 2024 approximately $12 to $17 million of expenses related to the cybersecurity incident, net of expected insurance recovery⁹.
The Company has also been named as a defendant in several lawsuits related to this cybersecurity incident, which are seeking various remedies, including monetary and injunctive relief. While we cannot presently quantify the full scope of expenses and other related impacts associated with this cybersecurity incident, including costs associated with any related current or future litigation or regulatory inquiries or investigations, the Company currently does not expect that the cybersecurity incident will have a material impact on its overall financial condition or on its ongoing results of operations¹⁰,¹¹.
Forward-Looking Statements
This Amendment contains “forward-looking statements” within the meaning of the federal securities laws. Forward-looking statements are made based on the Company’s expectations and beliefs concerning future events impacting the Company, and, therefore, involve several risks and uncertainties. You can identify these statements by the use of words such as “will,” “anticipate,” “estimate,” “expect,” “should,” “could” and “may” and similar expressions or the negative versions of these words or comparable words (however, the absence of these words or similar expressions does not mean that a statement is not forward-looking). All statements regarding the impact from the cybersecurity incident, including impact on the operations and financial condition of the Company, the scope of the investigation and the Company’s plans, objectives, projections and expectations relating to the Company’s operations or financial condition, and assumptions related thereto are forward-looking statements. Forward-looking statements are not guarantees and actual results could differ materially from those expressed or implied in the forward-looking statements. Potential risks and uncertainties that could cause the actual results of the Company’s operations or financial condition to differ materially from those expressed or implied by forward-looking statements include, but are not limited to: the Company’s ongoing assessment of the impacts of the cybersecurity incident and its impact on the Company’s operations and financial condition; the Company’s ongoing assessment and investigation of the incident, including the Company’s potential discovery of additional information related to the incident in connection with its investigation or otherwise; the impact of the cybersecurity incident on the Company’s relationships with customers, employees and regulators; legal, reputational and financial risks resulting from the cybersecurity incident; the extent of available insurance coverage; any regulatory inquiries and/or litigation filed in connection with this incident and associated costs; the Company’s ability to service its customers following the issue and any change in customer behavior as a result of the issue; the scope of personal information that was accessed or obtained by the unauthorized third party¹²,¹³ and the negative consequences of the illegal or improper use of such information by the unauthorized third party, such as fines, penalties, or loss of reputation, competitiveness or customers; and that any future, or still undetected, cybersecurity related incident, whether an attack, disruption, intrusion, denial of service, theft or other breach could result in unauthorized access to, or disclosure of, data, resulting in claims, costs and reputational harm that could negatively affect our actual results of operations or financial condition; and other risks detailed in the “Risk Factors” section of the Company’s Annual Report on Form 10-K for the year ended December 31, 2022 and Quarterly Reports on Form 10-Q as well as any subsequent filings with the Securities and Exchange Commission, including Forms 8-K filed or furnished with the SEC. The forward-looking statements in this document speak only as of the date of this Amendment. The Company does not undertake any obligation to publicly update or revise any forward-looking statement to reflect future events or circumstances, except as required by applicable law.
9.01. Financial Statements and Exhibits.
(d) Exhibits.
Exhibit No. | Description | |||| 104 | Cover Page Interactive Data File (embedded within the Inline XBRL document) |