14 unchanged sentences
• a third-party risk management process that includes internal vetting of certain third-party vendors and service providers with whom we may share data.
−Removed: Over the past fiscal year, we have not identified risks from known cybersecurity threats, including as a result of any prior cybersecurity incidents we have experienced from time to time, that have materially affected or are reasonably likely to materially affect us, including our operations, business strategy, operating results, or financial condition.
+Added: As previously disclosed on a Current Report on Form 8-K filed with the SEC on May 15, 2025, a threat actor improperly obtained information about certain customer accounts and internal documentation, and used that information for social-engineering attempts (the “Data Theft Incident”).
+Added: No passwords or private keys were compromised as a result of this incident.
+Added: During the year ended December 31, 2025, we paid $311.2 million of cash related to the Data Theft Incident, comprising voluntary customer reimbursements and direct legal costs.
+Added: We continue to face risks related to the Data Theft Incident, including harm to our reputation, and costs related to governmental investigations and regulatory scrutiny, and ongoing litigation.
+Added: Over the past fiscal year, except as set forth herein, we have not identified any cybersecurity-related risks that have materially impacted our operations, business strategy, operating results, or financial condition.
We will continue to monitor and assess our cybersecurity risk management program as well as invest in and seek to improve such systems and processes as appropriate.
−Removed: If we were to experience a material cybersecurity incident in the future, such incident may have a material effect, including on our operations, business strategy, operating results, or financial condition.
−Removed: For more information regarding cybersecurity risks that we face and potential impacts on our business related thereto, see the section titled “ Risk Factors ” in Part I, Item 1A of this Annual Report on Form 10-K.
+Added: If we were to experience any further material cybersecurity incidents in the future, such incidents may have a material effect, including
+Added: on our operations, business strategy, operating results, or financial condition.
+Added: For more information regarding cybersecurity risks that we face, including previous cybersecurity incidents, and potential impacts on our business related thereto, see the section titled “ Risk Factors ” in Part I Item 1A of this Annual Report on Form 10-K.
Cybersecurity Governance
1 unchanged sentence
The Audit Committee oversees management’s implementation of our cybersecurity risk management program, including processes and policies for determining risk tolerance, and reviews management’s strategies for adequately mitigating and managing identified risks, including risks relating to cybersecurity threats.
−Removed: The Audit Committee has established the Enterprise Risk Management Working Group (“ERMWG”), comprising members of our senior management team and other senior leaders, to provide executive oversight of our enterprise risk management program .
−Removed: Our Chief Security Officer (“CSO”) is a member of the ERMWG, and together with our Chief Information Security Officer (“CISO”) leads an ERMWG sub-working group related to cybersecurity, which meets periodically to review and discuss emerging and key risks relating to cybersecurity at the company, and to provide regular updates to the ERMWG.
−Removed: The Audit Committee receives updates from the ERMWG and from members of management, including our CSO and CISO, on our cybersecurity risks at its quarterly meetings, and reviews metrics about cyber threat response preparedness, program maturity milestones, risk mitigation status, and the current and emerging threat landscape.
+Added: The Audit Committee has established the Enterprise Risk Management Working Group (“ERMWG”), comprising members of our senior management team and other senior leaders, including our Chief Security Officer (“CSO”), to provide executive oversight of our enterprise risk management program.
+Added: The ERMWG receives updates on cybersecurity matters from various staff members, including our Chief Information Security Officer (“CISO”) .
+Added: The Audit Committee receives updates from members of management, including our CSO and CISO, on our cybersecurity risks at its quarterly meetings, and reviews metrics about cyber threat response preparedness, program maturity milestones, risk mitigation status, and the current and emerging threat landscape.
In addition, management updates the Audit Committee, as necessary, regarding any material cybersecurity threats or incidents, as well as any incidents with lesser impact potential.
2 unchanged sentences
Members of our board of directors receive presentations that include cybersecurity topics and the management of key cybersecurity risks from our CSO and CISO as part of the continuing education of our board of directors on topics that impact public companies.
−Removed: Finally, our board of directors annually reviews and is required to approve our Global Information Security Program Policy and any changes recommended by our CSO.
Our management team, including our CSO and CISO, is responsible for assessing and managing our material risks from cybersecurity threats and for our overall cybersecurity risk management program on a day-to-day basis, and supervises both our internal cybersecurity personnel and the relationship with our retained external cybersecurity consultants.
Our CSO’s and CISO’s experience includes years of working in the cybersecurity field in various industries, including the financial services industry .
−Removed: Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, including through periodic ERMWG sub-working group meetings;
+Added: Our management team supervises efforts to prevent, detect, mitigate, and remediate cybersecurity risks and incidents through various means, including through periodic ERMWG meetings;
briefings from internal security personnel;
2 unchanged sentences
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.