A Dark Vector Cognition product

Item 1A. Risk Factors

8K characters. Original on sec.gov · Markdown

Item 1A. Risk Factors

There have been no material changes to the Risk Factors disclosed in Item 1A of our Annual Report on Form 10-K for the fiscal year ended March 31, 2022 other than as discussed below. Because the Zynga Acquisition has now been consummated and Zynga’s business is expected to constitute a significant portion of our business, additional significant risks may apply to the combined business as detailed in the joint proxy statement/prospectus previously filed on April 7, 2022, and incorporated by reference herein (File No. 333-263511), including the risks relating to Zynga’s business as detailed in Exhibit 99.2 of the Form 8-K previously filed on April 6, 2022, and incorporated by reference herein.

We have updated the Risk Factor below (which was previously included in Item 1A of our Annual Report on Form 10-K for the fiscal year ended March 31, 2022) to reference the Cybersecurity Incident, which is discussed under “Part I, Item 2 – Management's Discussion and Analysis of Financial Condition and Results of Operations – Cybersecurity Incident.”

We rely on complex information technology systems and networks to operate our business. Any significant system or network disruption could have a negative impact on our business.

We rely on the efficient and uninterrupted operation of complex information technology systems and networks, some of which are within Take-Two and some of which are managed or hosted by third-party providers. All information technology systems and networks are potentially vulnerable to damage or interruption from a variety of sources, including but not limited to cyber-attacks, computer viruses, malicious software, security breaches, energy blackouts, natural disasters, terrorism, war, and telecommunication failures. We have also faced and in the future could face sophisticated attacks, including attacks referred to as advanced persistent threats, which are cyber-attacks aimed at compromising our intellectual property and other commercially sensitive information, such as the source code and game assets for our software or confidential customer or employee information, which remain undetected for prolonged periods of time. In September 2022, we experienced a network intrusion in which an unauthorized third party illegally accessed and downloaded confidential information from Rockstar Games’ systems, including early development footage for the next Grand Theft Auto. Subsequently, also in September 2022, an unauthorized third party illegally accessed credentials for a vendor platform that 2K Games uses to provide help desk support to its customers. See “Part I, Item 2 – Management's Discussion and Analysis of Financial Condition and Results of Operations – Cybersecurity Incident” for further discussion.

Information technology system disruptions, network failures, or security breaches (including the Cybersecurity Incident and similar incidents) have negatively affected, and in the future could negatively affect our business continuity, operations and financial results. These risks extend to the networks and e-commerce sites of console platform providers and other partners who sell or host our content online. The risk of such threats is heightened as a result of international conflicts such as the one between Russia and Ukraine and as a result of an extended period of remote work arrangements due to COVID-19. Along with our partners, we have expended, and expect to continue to expend, financial and operational resources to implement certain systems, processes and technologies to guard against cyber risks and to help protect our data and systems. However, the techniques used to exploit, disable, damage, disrupt or gain access to our networks, our products and services, supporting technological infrastructure, intellectual property and other assets change frequently, continue to evolve in sophistication and volume, and often are not detected for long periods of time. Our systems, processes and technologies, and the systems, processes and technologies of our business partners or our third-party service providers, have not been and in the future may not be adequate against all eventualities. In addition, the costs to respond to, mitigate, or notify affected parties of cyber-attacks and other security vulnerabilities are significant. Failures to prevent or mitigate security breaches or cyber risks, or detect or respond adequately to a security breach or cyber risk, could result in a loss of anticipated revenue, interruptions to our products and services, our having to incur significant remediation and notification costs, degrade the user experience, cause consumers to lose confidence in our products and services, and significant legal and financial costs. Additionally, applicable insurance policies may be insufficient to reimburse us for all such losses, and it is uncertain whether we will be able to maintain the current level of insurance coverage in the future on reasonable terms or at all.

Successful exploitation of our systems can have other negative effects upon the products, services, and user experience we offer. In particular, the virtual economies that we have established in many of our games are subject to abuse, exploitation and other forms of fraudulent activity that can negatively affect our business. Virtual economies involve the use of virtual currency or virtual assets that can be used or redeemed by a player within a particular game or service. Although we have implemented and continue to develop programs reasonably designed to prevent such negative impacts, the abuse or exploitation

of our virtual economies can include the illegitimate generation and sale of virtual items in black markets. These kinds of activities and the steps that we take to address and prevent these issues may result in a loss of anticipated revenue, interfere with players’ enjoyment of a balanced game environment and cause reputational harm.

Item 2. Unregistered Sales of Equity Securities and Use of Proceeds

Issuer Purchases of Equity Securities

Share Repurchase Program—Our Board of Directors previously authorized the repurchase of up to 21.7 shares of our common stock. The authorizations permit us to purchase shares from time to time through a variety of methods, including in the open market or through privately negotiated transactions, in accordance with applicable securities laws. Repurchases are subject to the availability of stock, prevailing market conditions, the trading price of the stock, our financial performance and other conditions. The program may be suspended or discontinued at any time for any reason.

During the three months ended September 30, 2022, we did not repurchase any shares of our common stock in the open market, as part of the program. As of September 30, 2022, we had repurchased a total of 11.7 shares of our common stock under this program, and 10.0 shares of common stock remained available for repurchase under our share repurchase program. The table below details the share repurchases made by us during the three months ended September 30, 2022:

PeriodShares purchasedAverage price per shareTotal number of shares purchased as part of publicly announced plans or programsMaximum number of shares that may yet be purchased under the repurchase program
July 1-31, 2022—$——10.0
August 1-31, 2022—$——10.0
September 1-30, 2022—$——10.0

Previous: Item 4. Controls and Procedures · Next: Item 6. Exhibits