Item 1A. Risk Factors.
7K characters. Original on sec.gov ·
Item 1A. Risk Factors.
In connection with information set forth in this Quarterly Report on Form 10-Q, the risk factors discussed under Item 1A. Risk Factors, in Part I of our 2025 Form 10-K and in our subsequent filings, including in this filing, should be considered. The risks set forth in our 2025 Form 10-K and in our subsequent filings, including in this filing, could materially and adversely affect our business, financial condition, and results of operations. Except as set forth below, there are no material changes from the risk factors as previously disclosed in our 2025 Form 10-K, in any of our subsequently filed reports or as otherwise set forth in this Quarterly Report.
Our business could be significantly harmed as a result of compromise of our electronic data.
We and our third-party manufacturers and other business partners maintain significant amounts of data electronically in locations around the world and in the cloud. This data relates to all aspects of our business, including current and future products and entertainment under development, and also contains certain customer, consumer, supplier, partner and employee data. We and our partners maintain systems and processes designed to protect this data, but notwithstanding such protective systems and processes, there have been, and in the future may be, intrusions, cyber-attacks, tampering, or other authorized access, whether intentional or unintentional, that have compromised, and could in the future, compromise the integrity and privacy of this data. Intrusions, cyber-attacks, tampering, and other unauthorized access continue to increase in frequency, sophistication and intensity, and are becoming increasingly difficult to detect and prevent. They are often carried out by motivated, well-resourced, skilled and persistent actors, including nation states, organized crime groups, “hacktivists” and employees or contractors acting with malicious intent. Intrusions, cyber-attacks, tampering, and other unauthorized access could include the deployment of harmful malware and key loggers, ransomware, a denial-of-service attack, a malicious website, artificial intelligence, the use of social engineering and other means to affect the confidentiality, integrity and availability of our or third-party technology systems and data. Intrusions, cyber-attacks, tampering, and other unauthorized access could also include supply chain attacks, which could cause a delay in the manufacturing of our products. In addition, we provide confidential and proprietary information to our third-party manufacturers and business partners to conduct our business. While we obtain assurances from those parties that they have systems
and processes in place to protect such data, and where applicable, that they will take steps to assure the protections of such data by third parties, those manufacturers and partners may also be subject to data intrusion or otherwise compromise the protection of such data. The risk of data loss or breaches is heightened during uncertain economic times, changes in business strategy and reductions in workforce. Any compromise of the confidential data of our customers, consumers, suppliers, partners, employees or ourselves, or failure to prevent or mitigate the loss of or damage to this data through breach of our information technology systems, or those of our third party manufacturers and other business partners, as well as any related security incident response, containment, remediation, or mitigation efforts, could substantially disrupt our operations, result in delays of shipping products, result in delays in making or receiving payments, harm our customers, consumers, employees and other business partners, damage our reputation, violate applicable laws and regulations, subject us to potentially significant costs and liabilities and/or result in a loss of business that could be material.
For example, in late March 2026, we identified unauthorized access to our network. Upon discovery, we promptly activated our security incident response protocols, implemented containment measures, including proactively taking certain systems offline, and launched an investigation with the assistance of third-party cybersecurity professionals. Based on analysis with the assistance of outside cybersecurity experts and information to date, we believe the unauthorized access has been contained and we are making progress in fully restoring our systems and operations.
Despite our efforts to control and remediate the impacts and risks related to the unauthorized access to our network, the duration and magnitude of the related operational disruption may be greater than we currently anticipate; the effectiveness of our response, our business continuity plans and our ongoing assessment of the impact of the unauthorized access may be inadequate and thus fail to prevent adverse effects on our business, operations, financial results, and financial reporting; and any further impacts related to the unauthorized access or other similar unauthorized activity may result in increased costs, including from any legal proceedings. For more information, refer to Part I, Item 2. “Management’s Discussion and Analysis of Financial Condition and Results of Operation – Unauthorized Network Access.”
Item 2. Unregistered Sales of Equity Securities and Use of Proceeds.
In February 2026, the Company announced that its Board of Directors authorized the repurchase of up to $1.0 billion in Common Stock, which may be repurchased in the open market or through privately negotiated transactions. This authorization replaces and supersedes all prior approved share repurchase authorization and has no expiration date. The Company has no obligation to repurchase shares under this authorization. The timing, actual number and value of the shares that are repurchased, if any, will depend on a number of factors, including the price of the Company’s stock and the Company's generation of, and uses for, cash.
During the three months ended March 29, 2026, the Company's discretionary share repurchases, in millions of dollars except shares and per share data, were as follows:
| 2026 Fiscal Month | Total Number of Shares Purchased | Average Price Paid per Share | Total Number of Shares Purchased as Part of Share Repurchase Authorization | Total Remaining Authorization | |||||||||||||||||||
| December 29 to January 25 | — | $ | — | — | $ | — | |||||||||||||||||
| January 26 to March 1 | — | $ | — | — | $ | 1,000 | |||||||||||||||||
| March 2 to March 29 | 82,559 | $ | 93.3 | 82,559 | $ | 992 | |||||||||||||||||
| 82,559 | $ | 93.3 | 82,559 |
Item 3. Defaults Upon Senior Securities.
None.
Item 4. Mine Safety Disclosures.
Not applicable.
Previous: Item 4. Controls and Procedures. · Next: Item 5. Other Information.