A Dark Vector Cognition product

Item 1A. Risk Factors

15K characters. Original on sec.gov · Markdown

Item 1A. Risk Factors

The information presented below supplements the risk factors set forth in our annual report on Form 10-K for the year ended December 31, 2021. In addition to the other information set forth in this report, you should carefully consider the factors discussed in Part I, Item 1A. "Risk Factors" in our Annual Report on Form 10-K for the year ended December 31, 2021 and Part II, Item 1A, "Risk Factors" in other reports we file with the Securities and Exchange Commission, from time to time, all of which could materially affect our business, financial condition or future results. There have been no material changes in our risk factors from those disclosed under the caption "Item 1A. Risk factors" to our annual report on Form 10-K for the year ended December 31, 2021, except as follows:

Risks Associated with the Conflict between Russia and Ukraine

The current conflict between Russia and Ukraine is creating substantial uncertainty about the role Russia will play in the global economy in the future. Although the extent, duration, severity and outcome of the ongoing military conflict between Russia and Ukraine is highly unpredictable, this conflict could lead to significant market and other disruptions. The escalation or continuation of this conflict presents heightened risks and has resulted and could continue to result in volatile commodity markets, supply chain disruptions, increased risk of cyber incidents or other disruptions to information systems, heightened risks to employee safety, significant volatility of the Russian ruble, limitations on access to credit markets, increased operating costs (including fuel and other input costs), the frequency and volume of failures to settle securities transactions, inflation, potential for increased volatility in commodity, currency and other financial markets, safety risks, and restrictions on the transfer of funds to and from Russia. We cannot predict how and the extent to which the conflict will affect our customers, operations or business partners or the demand for our products and our global business. Depending on the actions we take or are required to take, the ongoing conflict could also result in loss of assets or impairment charges. Additionally, we may also face negative publicity and reputational risk based on the actions we take or are required to take as a result of the conflict, which could damage our brand image or corporate reputation. The extent of the impact of these tragic events on our business remains uncertain and will continue to depend on numerous evolving factors that we are not able to accurately predict, including the duration and scope of the conflict. We will continue to monitor and assess the situation as circumstances evolve and to identify actions to potentially mitigate any unfavorable impacts on our future results.

In response to the Russian invasion of Ukraine, the United States, the European Union, the United Kingdom and other governments have imposed sanctions and other restrictive measures. Such sanctions, and other measures, as well as countersanctions or other responses from Russia or other countries have adversely affected, and will adversely affect, the global economy and financial markets and could adversely affect our business, financial condition and results of operations or otherwise aggravate the other risk factors that we identify herein or previously identified in our Annual Report on Form 10-K for the year ended December 31, 2021. We cannot predict the scope of future developments in sanctions, punitive actions or macroeconomic factors arising from the conflict. These measures are complex and still evolving. Our efforts to comply with such measures may be costly and time consuming and will divert the attention of management. Any alleged or actual failure to comply with these measures may subject us to government scrutiny, civil or criminal proceedings, sanctions, and other liabilities, which may have a material and adverse effect on our operations, financial condition, and results of operations. In light of all of these events, we have developed and are continuing to refine our business continuity plan and crisis response materials to mitigate the impact of disruptions to our business, but it is unclear if our plan will successfully mitigate all potential disruptions. If our business continuity plan fails to mitigate some or all disruptions, it could have a material and adverse effect on our business, financial condition, and results of operations.

Our business in Russia accounted for approximately 2.8% and 4.9% of our consolidated net revenues and net income for the year ended December 31, 2021, respectively, and accounted for approximately 3.1% and 6.1% of our consolidated net revenues and net income for the nine months ended September 30, 2022, respectively. Our assets in Russia were approximately 2.4% of our consolidated assets at December 31, 2021 and approximately 3.1% of our consolidated assets at September 30, 2022. The net book value of our assets in Russia at September 30, 2022 was approximately $255 million, of which $247 million is restricted cash. As described in Note 3 to our condensed consolidated financial statements, we currently have not recognized any impairment charges related to the assets of our Russian business. However, the extent, severity, duration and outcome of the conflict between Russia and Ukraine and related sanctions could potentially impact the value of our assets in Russia as the conflict continues. Our Russian business is part of our Fleet segment.

We may not be able to adequately protect our systems or the data we collect from continually evolving cybersecurity risks or other technological risks, which could subject us to liability and damage our reputation.

We electronically receive, process, store and transmit data and sensitive information about our customers and merchants, including bank account information, social security numbers, expense data, and credit card, debit card and checking account numbers. We endeavor to keep this information confidential; however, our websites, networks, information systems, services

and technologies may be targeted for sabotage, disruption or misappropriation. The uninterrupted operation of our information systems and our ability to maintain the confidentiality of the customer and consumer information that resides on our systems are critical to the successful operation of our business. Unauthorized access to our networks and computer systems could result in the theft or publication of confidential information or the deletion or modification of records or could otherwise cause interruptions in our service and operations.

Other than a previously disclosed unauthorized access incident during the second quarter of 2018, we are not aware of any material breach of our or our associated third parties’ computer systems, although we and others in our industry are regularly the subject of attempts by bad actors to gain unauthorized access to these computer systems and data or to obtain, change or destroy confidential data (including personal consumer information of individuals) through a variety of means.

Because techniques used to sabotage or obtain unauthorized access to our systems and the data we collect change frequently and may not be recognized until launched against a target, we may be unable to anticipate these techniques or to implement adequate preventative measures. Threats to our systems and our associated third parties’ systems can derive from human error, fraud or malice on the part of employees or third parties, or may result from accidental technological failure. Computer viruses can be distributed and could infiltrate our systems or those of our associated third parties. In addition, denial of service or other attacks could be launched against us for a variety of purposes, including to interfere with our services or create a diversion for other malicious activities. Although we believe we have sufficient controls in place to prevent disruption and misappropriation and to respond to such attacks, any inability to prevent security breaches could have a negative impact on our reputation, expose us to liability, decrease market acceptance of electronic transactions and cause our present and potential clients to choose another service provider.

In addition, the risk of cyber-attacks has increased in connection with the military conflict between Russia and Ukraine and the resulting geopolitical conflict. In light of those and other geopolitical events, nation-state actors or their supporters may launch retaliatory cyber-attacks, and may attempt to cause supply chain and other third-party service provider disruptions, or take other geopolitically motivated retaliatory actions that may disrupt our business operations, result in data compromise, or both. Nation-state actors have in the past carried out, and may in the future carry out, cyber-attacks to achieve their aims and goals, which may include espionage, information operations, monetary gain, ransomware, disruption, and destruction. In February 2022, the U.S. Cybersecurity and Infrastructure Security Agency issued a warning for American organizations noting the potential for Russia’s cyber-attacks on Ukrainian government and critical infrastructure organizations to impact organizations both within and beyond the United States, particularly in the wake of sanctions imposed by the United States and its allies. These circumstances increase the likelihood of cyber-attacks and/or security breaches.

We could also be subject to liability for claims relating to misuse of personal information, such as unauthorized marketing purposes and violation of data privacy laws. For example, we are subject to a variety of U.S. and international statutes, regulations, and rulings relevant to the direct email marketing and text-messaging industries. While we believe we are in compliance with the relevant laws and regulations, if we were ever found to be in violation, our business, financial condition, operating results and cash flows could be materially adversely affected. We cannot provide assurance that the contractual requirements related to security and privacy that we impose on our service providers who have access to customer and consumer data will be followed or will be adequate to prevent the unauthorized use or disclosure of data. In addition, we have agreed in certain agreements to take certain protective measures to ensure the confidentiality of customer data. The costs of systems and procedures associated with such protective measures, as well as the cost of deploying additional personnel, training our employees and hiring outside experts, may increase and could adversely affect our ability to compete effectively. Any failure to adequately enforce or provide these protective measures could result in liability, protracted and costly litigation, governmental and card network intervention and fines, remediation costs, and with respect to misuse of personal information of our customers, lost revenue and reputational harm. While we maintain insurance covering certain security and privacy damages and claim expenses we may not carry insurance or maintain coverage sufficient to compensate for all liability and such insurance may not be available for renewal on acceptable terms or at all, and in any event, insurance coverage would not address the reputational damage that could result from a security incident.

In addition, under payment network rules, regulatory requirements, and related obligations, we may be responsible for the acts or failures to act of certain third parties, such as third-party service providers, vendors, partners and others, which we refer to collectively as associated participants. The failure of our associated participants to safeguard cardholder data and other information in accordance with such rules, requirements and obligations could result in significant fines and sanctions and could harm our reputation and deter existing and prospective customers from using our services. We cannot assure you that there are written agreements in place with every associated participant or that such written agreements will ensure the adequate safeguarding of such data or information or allow us to seek reimbursement from associated participants. Any such unauthorized use or disclosure of data or information also could result in litigation that could result in a material adverse effect on our business, financial condition and results of operations.

Item 2. Unregistered Sales of Equity Securities and Use of Proceeds

The Company's Board of Directors (the "Board") has approved a stock repurchase program (as updated from time to time, the "Program") authorizing the Company to repurchase its common stock from time to time until February 1, 2024. On January 25, 2022, the Board increased the aggregate size of the Program by $1.0 billion, to $6.1 billion. Since the beginning of the Program through September 30, 2022, 25,699,551 shares have been repurchased for an aggregate purchase price of $5.7 billion, leaving the Company up to $0.4 billion of remaining authorization available under the Program for future repurchases in shares of its common stock.

On October 25, 2022, the Board increased the aggregate size of the Program by $1.0 billion to an aggregate of $7.1 billion, with approximately $1.4 billion remaining.

The following table presents information as of September 30, 2022, with respect to purchases of common stock of the Company made during the three months ended September 30, 2022 by the Company as defined in Rule 10b-18(a)(3) under the Exchange Act.

PeriodTotal Number of Shares PurchasedAverage Price Paid Per ShareTotal Number of Shares Purchased as Part of the Publicly Announced PlanMaximum Value that May Yet be Purchased Under the Publicly Announced Plan (in thousands)
July 1, 2022 through July 31, 2022931,260$215.1024,398,365$655,295
August 1, 2022 through August 31, 20221,301,144$230.5825,699,509$355,278
September 1, 2022 through September 30, 202242$212.5325,699,551$355,269
Item 3. Defaults Upon Senior Securities

Not applicable.

Item 4. Mine Safety Disclosures

Not applicable.

Previous: Item 4. Controls and Procedures · Next: Item 5. Other Information