A Dark Vector Cognition product

Item 1A. Risk Factors

21K characters. Original on sec.gov · Markdown

Item 1A. Risk Factors

Other than the risk factors set forth below, there have been no material changes from the risk factors disclosed in our Annual Report in response to Part I, Item 1A of Form 10-K. Additional risks not currently known to us or that we currently deem to be immaterial also may materially affect our business, results of operations, financial condition, and the price of our common stock.

The planned spin-off of FedEx Freight may not be completed on the terms or timeline currently contemplated, if at all, and there is no guarantee that the spin-off, if completed, will achieve the intended financial and strategic benefits. In December 2024, we announced our intention to separate FedEx Freight from our portfolio structure through the creation of a separate publicly traded company (“NewCo”). The planned separation, which would be implemented through the spin-off of shares of NewCo to FedEx stockholders, is expected to be tax-free for U.S. federal income tax purposes for FedEx stockholders and be completed by June 2026. Completion of the planned spin-off is subject to the final approval of our Board of Directors and will be dependent on a number of factors that may be beyond our control, including, among other things, market conditions, industry trends, the receipt and continuing validity of a private letter ruling from the Internal Revenue Service (“IRS”) and/or favorable opinions of our U.S. tax advisors with respect to the tax-free nature of the transaction, the receipt of other regulatory and contractual approvals, and the availability of financing for NewCo on satisfactory terms. The proposed spin-off is complex in nature, and unanticipated changes or developments could delay or prevent the completion of the spin-off or cause the spin-off to occur on terms or conditions that are different or less favorable than expected.

Whether or not we complete the spin-off, we may face significant challenges in connection with the transaction, including, without limitation:

the diversion of the attention of our Board of Directors and senior management from the pursuit of our business strategy and long-term planning and of our management and employees from day-to-day operations;

our ability to maintain NewCo’s continued support of our DRIVE transformation, Network 2.0, the redesign of the Federal Express international air network, and other strategic initiatives;

our ability to maintain operational, commercial, data and information technology, brand and intellectual property, human resources, finance, legal, sales, and marketing continuity where necessary between FedEx and NewCo and establish stand-alone functions and infrastructure at NewCo where necessary;

- 42 -

the risk that if the IRS determines that certain steps of the planned spin-off do not qualify for tax-free treatment for U.S. federal income tax purposes, FedEx and its stockholders could incur significant tax liabilities;

costs and expenses related to the planned spin-off (which are expected to be significant), including costs related to commercial and operational dis-synergies; restructuring and other transaction expenses; expenses related to establishing stand-alone operational, commercial, personnel, and digital and technology infrastructure at NewCo; and accounting, tax, legal, and other professional services expenses, any of which may be higher than initially expected;

retaining existing business and operational relationships, including with customers, suppliers, employees, and other counterparties;

addressing employee issues so as to promote retention and motivation and maintain efficient and effective labor and employee relations;

obtaining any required regulatory licenses, operating authority, or contractual consents;

determining the appropriate allocations of assets and liabilities between FedEx and NewCo, as well as the terms governing the relationship between FedEx and NewCo following the spin-off; and

potential negative reactions from investors and other external stakeholders.

There can be no assurance that the spin-off, if completed, will achieve the intended financial and strategic benefits (which are based on a number of assumptions, some or all of which may prove to be incorrect) or provide greater value to our stockholders than that reflected in the current price of our common stock, or that the dis-synergies of the transaction (including costs of related restructuring transactions) will not exceed the anticipated amounts. The market price of our common stock could be subject to significant fluctuation or otherwise be adversely affected by the uncertainties described above. Changes in the stockholder base of FedEx and/or NewCo following the planned spin-off could also cause the price of either company’s common stock to fluctuate.

If the planned spin-off occurs, FedEx and NewCo will each be smaller, less diversified companies with more concentrated areas of focus. As a result, FedEx and NewCo may become more vulnerable to changing macroeconomic and market conditions; the results of operations, cash flows, effective tax rate, and other financial and operating metrics of each company may be subject to increased volatility; and the ability of each company to fund capital expenditures and investments, pay dividends, and service debt may be diminished.

To the extent challenges related to the planned spin-off of NewCo adversely affect our business, they may also have the effect of heightening other risks disclosed in our Annual Report, any of which could materially and adversely affect our business, results of operations, and the price of our common stock. Such risks include, but are not limited to, our ability to execute our DRIVE transformation, Network 2.0, and broader business strategy and effectively respond to changes in market dynamics and customer preferences; disruptions to our technology infrastructure, including through cyberattack or cyber-intrusion, ransomware attack, or malware attack; our ability to achieve or demonstrate progress on our goal of carbon neutrality for our global operations by calendar 2040; and our ability to maintain our strong reputation and the value of the FedEx brand.

A significant data breach or other disruption to our technology infrastructure could disrupt our operations and result in the loss of critical sensitive or confidential information, adversely affecting our reputation, business, or results of operations. Our ability to attract and retain customers, efficiently operate our businesses, execute our DRIVE transformation, and compete effectively increasingly depend in part upon the sophistication, security, and reliability of our technology network, including our ability to provide features of service that are important to our customers, to protect our confidential business information and the information provided by our customers, and to maintain customer confidence in our ability to protect our systems and to provide services consistent with their expectations. For example, we rely on information technology to receive shipment information in advance of physical receipt of packages, to track items that move through our delivery systems, to efficiently plan deliveries, to clear shipments through customs, to execute billing processes, and to track and report financial and operational data. We are subject to risks imposed by data breaches and operational disruptions, both random and targeted, including through cyberattack or cyber-intrusion, ransomware attack, malware attack, or denial of service attack by computer hackers, foreign governments and state-sponsored actors, cyber terrorists and hacktivists, cyber criminals, malicious employees or other insiders of FedEx or third-party service providers, and other groups and individuals. Data breaches and other technology disruptions of companies and governments continue to increase as the number, intensity, and sophistication of attempted attacks and intrusions from around the world have increased and we, our customers, and third parties increasingly store and transmit data by means of connected information technology systems. Additionally, risks such as code anomalies, “Acts of God,” transitional challenges in migrating operating company functionality to our FedEx enterprise automation platforms, data leakage, cyber-fraud, and human error pose a direct threat to our products, services, systems, and data and could result in unauthorized or block legitimate access to sensitive or confidential data regarding our operations, customers, employees, and suppliers, including personal information.

- 43 -

The technology infrastructure of acquired businesses, as well as their practices related to the use and maintenance of data, could also present issues that we were not able to identify prior to the acquisition. For example, ShopRunner, which we acquired in 2021, collects and stores certain personal data of its merchants and their buyers, its partners, consumers with whom it has a direct relationship, and users of its applications. Additionally, it uses third-party service providers and subprocessors to help deliver services to merchants and their buyers. These service providers and subprocessors may store or access personal data and/or other confidential information. The foregoing factors increase the risk of data incidents and the amount of potential exposure in the event of a data breach.

We also depend on and interact with the technology and systems of third parties, including our customers and third-party service providers such as cloud service providers and delivery services. Certain third parties host, process, or have access to information we maintain about our company, customers, employees, and vendors and/or operate systems that are critical to our business operations and services. Like us, these third parties are subject to risks imposed by data breaches, cyberattacks, and other events or actions that could damage, disrupt, or close down their networks or systems. We have security processes, protocols, and standards in place, including contractual provisions requiring such security measures, that are applicable to such third parties and are designed to protect information that is held by them, or to which they have access, as a result of their engagements with us. A cyberattack has and may in the future defeat one or more of such third parties’ security measures, allowing an attacker to obtain information about our company, customers, employees, and vendors or disrupt our operations. Certain third parties also have and may in the future experience operational disruptions or human error that could result in unauthorized access to sensitive or confidential data regarding our operations, customers, employees, and suppliers, including personal information. See “Failure of third-party service providers to perform as expected, or disruptions in our relationships with those providers or their provision of services to FedEx, could have a material adverse effect on our business and results of operations” under “Item 1A. Risk Factors” of our Annual Report for more information. The information systems of one of our third-party service providers recently experienced a security breach that resulted in unauthorized access to the third-party’s cloud environment, including certain systems that contained our data. To date this incident has not had a material adverse effect on our business or results of operations. However, there can be no assurance that this incident or similar events will not have such an effect in the future.

From time to time we experience disruptions to our complex, global technology infrastructure, including our computer systems and websites. Such events could result in the loss of confidential business or customer information; require substantial repairs or replacements, resulting in significant costs; and lead to the temporary or permanent transfer by customers of some or all of their business to our competitors. The foregoing could harm our reputation and adversely affect our business, customer service, and results of operations. Additionally, a security breach could require us to devote significant management resources to address the problems created. These types of adverse effects could also occur in the event the confidentiality, integrity, or availability of company and customer information was compromised due to a data loss by FedEx or a trusted third party.

We or the third parties with which we share information may not discover any security breach and loss of information for a significant period of time after the security breach occurs. Even if we detect a cybersecurity incident, the nature and extent of the incident may not be immediately clear. It may also not be clear how best to contain and remediate any harm caused by the cybersecurity incident, and certain errors or actions could be repeated or compounded before they are discovered and remediated. Based on the sophistication of threat actors and the size and complexity of our information systems and network environment, among other factors, an investigation into a cybersecurity incident could take a significant amount of time to complete. In addition, while the investigation of a cybersecurity incident is ongoing, we may not know the full extent of the harm caused by a threat actor, and such harm may spread both internally and to certain customers, vendors, or other third parties. Additionally, our logging capabilities and the logging capabilities of third parties are not always complete or sufficiently detailed, which could affect our ability to fully investigate and understand the scope of security events. Given the age, size, and complexity of our computer systems and network environment, patches for certain vulnerabilities may not exist and, even where patches or other risk-mitigating activities are available, the development of patches or execution of risk-mitigating actions may not occur before an underlying vulnerability is exploited or results in the compromise of our information systems or data. A significant number of our employees as well as customers and others with whom we do business continue to work remotely or in hybrid models, which may heighten these risks. These risks may also be heightened by our DRIVE transformation, including Network 2.0 and our recently completed one FedEx consolidation.

Furthermore, we are subject to an increasing number of cybersecurity compliance and reporting obligations in different jurisdictions that vary in their scope and application, creating conflicting reporting requirements. These factors and the time spent to comply may inhibit our ability to quickly provide complete and reliable information about the cybersecurity incident to customers, counterparties, and regulators, as well as the public. Any or all of these factors could further increase the costs and consequences of a cybersecurity incident on our business and results of operations. See “Our business is subject to complex and evolving U.S. and foreign laws and regulations regarding data protection.” under “Item 1A. Risk Factors” of our Annual Report for additional information on risks related to legal and regulatory developments with respect to data protection.

We have invested and continue to invest in technology security initiatives, information-technology risk management, business continuity, and disaster recovery plans, including investments to retire and replace end-of-life systems. The development and maintenance of these measures is costly and requires ongoing monitoring and updating as technologies change and efforts to

- 44 -

overcome security measures become increasingly more frequent, intense, and sophisticated. Despite our efforts, we are not fully insulated from data breaches, technology disruptions, data loss, and cyber-fraud, which could adversely affect our competitiveness and results of operations. See “Item 1A. Risk Factors” of our Annual Report on Form 10-K for the year ended May 31, 2021 for information regarding the 2017 NotPetya cyberattack at TNT Express and immaterial cyber incidents we experienced in 2017 and 2018. Additionally, we and our third-party service providers, vendors, and suppliers have experienced repeated attempts by cyber criminals, some of which have been successful, to gain access to customer accounts for the purposes of fraudulently diverting and misappropriating items being transported in our network, fraudulently charging shipment fees to customer or franchisee accounts, and fraudulently sending e-mails to recipients purporting to be from FedEx. To date, none of these fraudulent cyber activities have caused a material disruption to our systems or resulted in any material costs to FedEx.

Our security processes and initiatives may be unable to detect or prevent a breach or disruption in the future. Additionally, the rapid ongoing evolution and increased adoption of emerging technologies such as artificial intelligence and machine learning may make it more difficult to anticipate and implement protective measures to recognize, detect, and prevent the occurrence of any of the cyber events described above. While we have insurance coverage designed to address certain aspects of cyber risks in place, we cannot be certain that such coverage will be sufficient to cover claims, that we will continue to be able to obtain such coverage in amounts we deem sufficient, that our insurance carriers will pay on our insurance claims, or that we will not experience a claim for which coverage is not provided.

Item 2. Unregistered Sales of E****quity Securities and Use of Proceeds

Unregistered Sales of Equity Securities

On February 4, 2025, we acquired RouteSmart Technologies, Inc. (“RouteSmart”), a global leader in route planning and optimization solutions. The consideration paid to certain former stockholders of RouteSmart consisted in part of 359,052 unregistered shares of our common stock valued at approximately $90 million as of the acquisition date.

The foregoing transaction did not involve any underwriters or underwriting discounts or commissions. The shares of our common stock were issued in reliance upon the exemption from registration provided by Section 4(a)(2) of the Securities Act of 1933, as amended, in a privately negotiated transaction not involving any public offerings or solicitations. See Note 5 of the accompanying unaudited condensed consolidated financial statements for additional information regarding this transaction.

Issuer Purchases of Equity Securities

The following table provides information on FedEx’s repurchases of our common stock during the third quarter of 2025:

PeriodTotal Number of Shares PurchasedAverage Price Paid per ShareTotal Number of Shares Purchased as Part of Publicly Announced ProgramApproximate Dollar Value of Shares That May Yet Be Purchased Under the Program ($ in millions)
Dec. 1-31, 2024540,000$276.78540,000$2,911
Jan. 1-31, 20251,258,310$276.031,258,310$2,564
Feb. 1-28, 2025—$——$2,564
Total1,798,3101,798,310$2,564

In March 2024, our Board of Directors authorized a stock repurchase program for repurchases of up to $5.0 billion of FedEx common stock. As part of the 2024 repurchase program, we repurchased 1.8 million shares for $497 million in the open market during the third quarter of 2025. As of March 20, 2025, approximately $2.6 billion remained available to be used for repurchases under the 2024 stock repurchase program. Shares under the program may be repurchased from time to time in the open market or in privately negotiated transactions. No time limits were set for completion of the program; however, we may decide to suspend or discontinue the program.

See Note 1 of the accompanying unaudited condensed consolidated financial statements for additional information and “Item 2. Management’s Discussion and Analysis of Results of Operations and Financial Condition – Financial Condition – Liquidity Outlook” for information regarding potential stock repurchases during the remainder of 2025.

Previous: Item 1. Legal Proceedings · Next: Item 5. Other Information