Item 1A. RISK FACTORS

6K characters. Original on sec.gov · Markdown

Item 1A. RISK FACTORS

Other than the risk factor listed below, there have been no material changes to the risk factors disclosed in Part I, Item 1A of our 2025 Annual Report.

Unauthorized access to our or our customers’ information and systems could negatively impact our business.

Our systems and networks, as well as those of our customers, suppliers, service providers, and banks, have been, or may in the future become the target of cyberattacks or information security breaches which, in turn, could result in the unauthorized release and misuse of confidential or proprietary information about our company, our employees or our customers, as well as disrupt our operations or damage our facilities or those of third parties. Attacks on information systems and networks are increasing in their frequency, levels of persistence, sophistication, and intensity, and they are being conducted by increasingly sophisticated and organized groups and individuals, including state-sponsored organizations, with a wide range of motives and expertise.

For example, in May 2026, we experienced a material cybersecurity attack in which certain data was exfiltrated by an unauthorized party and certain systems were encrypted. Upon initial detection of an intrusion, we promptly activated our incident response protocols (including proactively taking systems offline globally for containment purposes), notified law enforcement, and engaged external cyber-forensic experts. The incident and our response temporarily disrupted our global operations. We have taken steps intended to mitigate the risk of dissemination of the exfiltrated data. This incident has been contained and our operations have fully recovered.

Techniques used to gain unauthorized access to or to acquire data and systems, disable or degrade service, or sabotage systems, are constantly evolving (including through the use of artificial intelligence), and we are unable to anticipate all techniques or comprehensively avoid unauthorized access, acquisition of, or other adverse impacts to our data or our systems or the networks and systems of third parties upon which we rely. We may not discover all such incidents or activities or be able to respond or otherwise address them promptly, in sufficient respects or at all.

Table of Contents

Additionally, our systems are subject to regulations to preserve the privacy of certain data held on those systems. We maintain an extensive network of technical security controls, policy enforcement mechanisms and monitoring systems, in order to address these threats. While these measures are designed to prevent, detect and respond to unauthorized activity in our systems, certain types of attacks could result in financial or information losses and/or reputational harm. If we cannot comply with regulations or prevent the unauthorized access, release and/or corruption of our or our customers’ confidential, classified or personally identifiable information, our reputation could be damaged, and/or we could face financial losses.

An adverse impact to the availability, integrity, or confidentiality of our information technology systems or data, or the information technology systems or data of third parties upon which we rely, could require us to incur additional costs to modify or enhance our systems, or to try to prevent or remediate any such attacks. Modifying or enhancing our systems may result in unanticipated or prolonged disruption events, which could have a material adverse effect on our business and/or results of operations.

The costs of mitigating data security risks could be significant and are likely to increase in the future. Although we carry cybersecurity insurance, there can be no assurance that our limits are sufficient to cover us against all potential losses for damages or fines in an amount exceeding our policy limits, or that applicable insurance will be available to us in the future on economically reasonable terms or at all.

ITEM 2. UNREGISTERED SALES OF EQUITY SECURITIES AND USE OF PROCEEDS

The following table shows information with respect to purchases of our common stock made during the three months ended June 30, 2026 by us or any of our “affiliated purchasers” as defined in Rule 10b-18(a)(3) under the Exchange Act:

PeriodTotal number of shares purchased (1)Average price paid per share (1)Total number of shares purchased as part of publicly announced plans or programs (1)Approximate dollar value of shares that may yet be purchased under the plans or programs (1)
April 1 - 30, 2026273,854$269.93273,854$630,070,000
May 1 - 31, 2026134,771$309.50134,771588,360,000
June 1 - 30, 2026129,966$328.13129,966545,720,000
Total538,591$290.82538,591545,720,000

(1)In February 2026, the Company’s Board of Directors authorized a new share repurchase program for the purchase of up to $1.0 billion of the Company’s common stock in open-market transactions, block transactions, through derivative transactions, privately negotiated transactions, or otherwise, including pursuant to any trading plan entered into by the Company under Rule 10b5-1 of the Exchange Act. This share repurchase program has no expiration date and it may be suspended or terminated at any time.

Previous: Item 4. . CONTROLS AND PROCEDURES · Next: Item 5. OTHER INFORMATION