−Removed: Other than the updated risk factors below, there have been no material changes in our risk factors as previously disclosed in Part I, Item 1A of our Annual Report on Form 10-K for the year ended December 31, 2020.
−Removed: Our Fifth Amended and Restated Certificate of Incorporation designates the Court of Chancery of the State of Delaware as the sole and exclusive forum for certain actions and proceedings, which could limit the ability of our stockholders to obtain a judicial forum of their choice for disputes with the Company or its directors, officers or employees.
−Removed: Our Fifth Amended and Restated Certificate of Incorporation (the “Certificate of Incorporation”) provides that, unless we consent in writing to the selection of an alternative forum, the Court of Chancery of the State of Delaware shall be the sole and exclusive forum for (i) any derivative action or proceeding brought on behalf of the Company, (ii) any action asserting a claim of breach of a fiduciary duty owed by any director, officer or employee of the Company to the Company or its stockholders, (iii) any action asserting a claim arising pursuant to any provision of the General Corporation Law of the State of Delaware, the Certificate of Incorporation or the Company's bylaws or (iv) any other action asserting a claim arising under, in connection with, and governed by the internal affairs doctrine.
−Removed: This choice of forum provision does not waive our compliance with our obligations under the federal securities laws and the rules and regulations thereunder.
−Removed: Moreover, the provision does not apply to suits brought to enforce a duty or liability created by the Exchange Act or by the Securities Act of 1933, as amended.
−Removed: This choice of forum provision may increase costs to bring a claim, discourage claims or limit a stockholder's ability to bring a claim in a judicial forum that the stockholder finds favorable for disputes with the Company or its directors, officers or employees, which may discourage such lawsuits against the Company and its directors, officers and employees, even though an action, if successful, might benefit our stockholders.
−Removed: Alternatively, if a court were to find the choice of forum provision to be inapplicable or unenforceable in an action, we may incur additional costs associated with resolving such matters in other jurisdictions, which could increase our costs of litigation and adversely affect our business and financial condition.
−Removed: Our business and Sprint’s business may not be integrated successfully or such integration may be more difficult, time consuming or costly than expected.
−Removed: Operating costs, customer loss and business disruptions, including challenges in maintaining relationships with employees, customers, suppliers or vendors, may be greater than expected.
−Removed: The combination of two independent businesses is complex, costly and time-consuming, and may divert significant management attention and resources.
−Removed: This process may disrupt our business or otherwise impact our ability to compete.
−Removed: The overall combination of our and Sprint’s businesses may also result in material unanticipated problems, expenses, liabilities, competitive responses and impacts, and loss of customers and other business relationships.
−Removed: The difficulties of combining the operations of the companies include, among others:
−Removed: • diversion of management attention to integration matters;
−Removed: • difficulties in integrating operations and systems, including intellectual property and communications systems, administrative and information technology infrastructure, and supplier and vendor arrangements;
−Removed: • challenges in conforming standards, controls, procedures and accounting and other policies;
−Removed: • alignment of key performance measurements may result in a greater need to communicate and manage clear expectations while we work to integrate and align policies and practices;
−Removed: • difficulties in integrating employees;
−Removed: • the transition of management to the combined company management team, and the need to address possible differences in corporate cultures, management philosophies, and compensation structures;
−Removed: • challenges in retaining existing customers and obtaining new customers;
−Removed: • difficulties in managing the expanded operations of a significantly larger and more complex company;
−Removed: • any disruptions to the operations and business in the Shentel service area following the Company’s acquisition of Wireless Assets (as defined in Note 2 – Business Combinations of the Notes to the Condensed Consolidated Financial Statements) as a result of the transition of such assets to the Company;
−Removed: • compliance with Government Commitments relating to national security;
−Removed: • known or potential unknown liabilities of Sprint that are larger than expected;
−Removed: • other potential adverse consequences and unforeseen increased expenses or liabilities associated with the Transactions.
−Removed: Additionally, uncertainties over the integration process could cause customers, suppliers, distributors, dealers, retailers and others to seek to change or cancel our existing business relationships or to refuse to renew existing relationships.
−Removed: Suppliers, distributors and content and application providers may also delay or cease developing new products for us that are necessary for the operations of our business due to uncertainties.
−Removed: Competitors may also target our existing customers by highlighting potential uncertainties and integration difficulties.
−Removed: Some of these factors are outside our control, and any one of them could result in lower revenues, higher costs and diversion of management time and energy, which could adversely impact our business, financial condition and operating results.
−Removed: In addition, even if the integration is successful, the full benefits of the Transactions including, among others, the synergies, cost savings or sales or growth opportunities may not be realized within the anticipated time frames or at all.
−Removed: We have recently experienced a criminal cyberattack and could in the future be further harmed by disruption, data loss or other security breaches, whether directly or indirectly.
−Removed: Our business involves the receipt, storage and transmission of our customers’ confidential information, including sensitive personal information and payment card information, confidential information about our employees and suppliers, and other sensitive information about our Company, such as our business plans, transactions and intellectual property (collectively, “Confidential Information”).
−Removed: Unauthorized access to Confidential Information is difficult to anticipate, detect or prevent, particularly given that the methods of unauthorized access constantly change and evolve.
−Removed: We and our third-party service providers are subject to attacks and threats to our and their IT networks, systems and supply chain, including attacks and threats by state-sponsored parties, malicious actors, employees or third parties, who may exploit bugs, errors, misconfigurations or other vulnerabilities that can compromise the confidentiality and integrity of Confidential Information or cause serious operational disruptions (e.g., ransomware).
−Removed: As a telecommunications carrier, we are considered a critical infrastructure provider and therefore are likely to be the target of cyberattacks (e.g., denial of service and other malicious attacks).
−Removed: In addition, the Pandemic has presented additional operational and cybersecurity risks to our IT systems due to work-from-home arrangements at the Company and our providers.
−Removed: Attacks against companies like ours are perpetrated by a variety of groups or persons, including those in jurisdictions where law enforcement measures to address such attacks are ineffective or unavailable, and such attacks may even be perpetrated by or at the behest of foreign governments.
−Removed: In addition, we provide confidential, proprietary and personal information to third-party service providers as part of our business operations.
−Removed: These third-party service providers have experienced data breaches and other attacks that included unauthorized access to Confidential Information and operational disruptions in the past, and face security challenges common to all parties that collect and process information.
−Removed: In August 2021, we disclosed that our systems were subject to a criminal cyberattack that compromised the data of millions of our current customers, former customers, and prospective customers, including, in some instances, social security numbers, names, addresses, dates of birth and driver’s license/identification numbers.
+Added: Other than the updated risk factor below, there have been no material changes in our risk factors as previously disclosed in Part I, Item 1A of our Annual Report on Form 10-K for the year ended December 31, 2021.
+Added: We have experienced criminal cyberattacks and could in the future be further harmed by disruption, data loss or other security breaches, whether directly or indirectly through third parties.
+Added: Our business involves the receipt, storage, and transmission of confidential information about our customers, such as sensitive personal, account and payment card information, confidential information about our employees and suppliers, and other sensitive information about our Company, such as our business plans, transactions, financial information, and intellectual property (collectively, “Confidential Information”).
+Added: We are subject to persistent cyberattacks and threats to our networks, systems, and supply chain from a variety of bad actors, many of whom attempt to gain access to and compromise Confidential Information by exploiting bugs, errors, misconfigurations or other vulnerabilities in our networks and other systems (including purchased and third-party systems) or engaging in credential harvesting or social engineering.
+Added: In some cases, these bad actors may obtain unauthorized access to Confidential Information utilizing credentials taken from our customers, employees, or third parties.
+Added: Other bad actors aim to cause serious operational disruptions to our business or networks through other means, such as through ransomware or distributed denial of services attacks.
+Added: Cyberattacks against companies like ours have increased in frequency and potential harm over time, and the methods used to gain unauthorized access constantly evolve, making it increasingly difficult to anticipate, prevent, and/or detect incidents successfully in every instance.
+Added: They are perpetrated by a variety of groups and persons, including state-sponsored parties, malicious actors, employees, contractors, or other unrelated third parties.
+Added: Some of these persons reside in jurisdictions where law enforcement measures to address such attacks are ineffective or unavailable, and such attacks may even be perpetrated by or at the behest of foreign governments.
+Added: In addition, we routinely provide certain Confidential Information to third-party providers whose products and services are used in our business operations, including as part of our IT systems, such as cloud services.
+Added: These third-party providers have experienced in the past, and will continue to experience in the future, cyberattacks that involve attempts to obtain unauthorized access to our Confidential Information and/or to create operational disruptions that could adversely affect our business, and these providers also face other security challenges common to all parties that collect and process information.
+Added: In August 2021, we disclosed that our systems were subject to a criminal cyberattack that compromised certain data of millions of our current customers, former customers, and prospective customers, including, in some instances, social security numbers, names, addresses, dates of birth and driver’s license/identification numbers.
With the assistance of outside cybersecurity experts, we located and closed the unauthorized access to our systems and identified current, former, and prospective customers whose information was impacted and notified them, consistent with state and federal requirements.
−Removed: We have incurred certain cyberattack-related expenses and expect to continue to incur additional expenses in future periods, including costs to investigate and remediate the attack, send notifications to customers and provide additional customer support and enhance customer protection.
+Added: We have incurred certain cyberattack-related expenses, including costs to remediate the attack, provide additional customer support and enhance customer protection, and expect to incur additional expense in future periods resulting from the attack.
For more information, see “Cyberattack” in the Overview section of MD&A.
−Removed: As a result of this cyberattack, we are subject to numerous lawsuits and regulatory inquiries, the ongoing costs of which may be material, and we may be subject to further regulatory inquiries and private litigation.
−Removed: For more information, see “– Contingencies and Litigation – Litigation and Regulatory Matters” in Note 13 – Commitments and Contingencies of the Notes to the Consolidated Financial Statements, and “– Unfavorable outcomes of legal proceedings may adversely affect our business, reputation, financial condition, cash flows and operating results” below.
−Removed: As a result of this cyberattack or other cyberattacks or security breaches involving our Company or our third-party suppliers, we may incur significant costs or experience other material financial impacts, which may not be covered by, or may exceed the coverage limits of, our cyber insurance, and such costs and impacts may have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
−Removed: In addition to the August 2021 cyberattack, we have previously experienced other incidents involving unauthorized access to certain Confidential Information, and we expect to experience cyberattacks and other cybersecurity incidents in the future.
−Removed: Typically, these incidents have involved attempts to commit fraud by taking control of a customer’s phone line.
−Removed: In other cases, the incidents have also involved unauthorized access to certain of our customers’ private information, including credit card information, financial data, social security numbers or passwords.
−Removed: Our procedures and safeguards to prevent unauthorized access to sensitive data and to defend against attacks seeking to disrupt our services must be continually evaluated and revised to address the ever-evolving threat landscape and changing cybersecurity regulations, which could require the investment of significant resources.
−Removed: We cannot make assurances that all preventive actions taken will adequately repel a significant attack or prevent security breaches or misuses of data, unauthorized access by third parties or employees or exploits against third-party supplier environments, or that we or our third-party suppliers will be able to effectively identify, investigate or remediate such incidents.
−Removed: We expect to continue to be the target of cyberattacks, data breaches or security incidents, given the nature of our business.
−Removed: Any future cyberattacks, data breaches, or security incidents may have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
−Removed: Unfavorable outcomes of legal proceedings may adversely affect our business, reputation, financial condition, cash flows and operating results.
−Removed: We and our affiliates are involved in various disputes, governmental and/or regulatory inspections, investigations and proceedings and litigation matters.
−Removed: Such legal proceedings can be complex, costly, and highly disruptive to our business operations by diverting the attention and energy of management and other key personnel.
−Removed: In connection with the Transactions, it is possible that stockholders of T-Mobile and/or Sprint may file putative class action lawsuits or shareholder derivative actions against the Company and the legacy T-Mobile board of directors and/or the legacy Sprint board of directors.
−Removed: Among other remedies, these stockholders could seek damages.
−Removed: The outcome of any litigation is uncertain and any such potential lawsuits could result in substantial costs and may be costly and distracting to management.
−Removed: Additionally, on April 1, 2020, in connection with the closing of the Merger, we assumed the contingencies and litigation matters of Sprint.
−Removed: Those matters include a wide variety of disputes, claims, government agency investigations and enforcement actions and other proceedings, including, among other things, certain ongoing FCC and state government agency investigations into Sprint’s Lifeline program.
−Removed: In September 2019, Sprint notified the FCC that it had claimed monthly subsidies for serving customers even though those customers may not have met usage requirements under Sprint’s usage policy for the Lifeline program due to an inadvertent coding issue in the system used to identify qualifying customer usage that occurred in July 2017 while the system was being updated.
−Removed: Sprint has made a number of payments to reimburse the federal government and certain states for excess subsidy payments.
−Removed: Unfavorable resolution of these matters could require making additional reimbursements and paying additional fines and penalties.
−Removed: On February 28, 2020, we received a Notice of Apparent Liability for Forfeiture and Admonishment from the FCC, which proposed a penalty against us for allegedly violating Section 222 of the Communications Act and the FCC’s regulations governing the privacy of customer information.
−Removed: We recorded an accrual for an estimated payment amount as of March 31, 2020, which was included in Accounts payable and accrued liabilities in our Consolidated Balance Sheets.
−Removed: As a result of the August 2021 cyberattack, we are subject to numerous lawsuits, including multiple class action lawsuits seeking unspecified monetary damages, and inquiries by various government agencies, law enforcement and other governmental authorities, and we may be subject to further regulatory inquiries and private litigation.
−Removed: We are cooperating fully with regulators and vigorously defending against the class action and other lawsuits.
−Removed: In light of the inherent uncertainties involved in these proceedings and inquiries, as of the date of this Quarterly Report, we have not recorded any accruals for losses related to these proceedings and inquiries, as any such amounts are not yet probable or estimable.
−Removed: We believe it is reasonably possible that we could incur losses associated with these proceedings and inquiries, and we will continue to evaluate information as it becomes known and will record an estimate for losses at the time or times when it is both probable that a loss has been incurred and the amount of the loss is reasonably estimable.
−Removed: Ongoing legal and other costs related to these proceedings and inquiries, as well as any potential future proceedings and inquiries, may be substantial, and losses associated with any adverse judgments, settlements, penalties or other resolutions of such proceedings and inquiries could be significant and have a material adverse impact on our business, reputation, financial condition, cash flows and operating results.
−Removed: We, along with equipment manufacturers and other carriers, are subject to current and potential future lawsuits alleging adverse health effects arising from the use of wireless handsets or from wireless transmission equipment such as cell towers.
−Removed: In addition, the FCC has from time to time gathered data regarding wireless device emissions, and its assessment of the risks associated with using wireless devices may evolve based on its findings.
−Removed: Any of these allegations or changes in risk assessments could result in customers purchasing fewer devices and wireless services, could result in significant legal and regulatory
−Removed: liability, and could have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
−Removed: The assessment of the outcome of legal proceedings, including our potential liability, if any, is a highly subjective process that requires judgments about future events that are not within our control.
−Removed: The amounts ultimately received or paid upon settlement or pursuant to final judgment, order or decree may differ materially from amounts accrued in our financial statements.
−Removed: In addition, litigation or similar proceedings could impose restraints on our current or future manner of doing business.
−Removed: Such potential outcomes including judgments, awards, settlements or orders could have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
−Removed: Our business may be impacted by new or amended tax laws or regulations or administrative interpretations and judicial decisions affecting the scope or application of tax laws or regulations .
−Removed: In connection with the products and services we sell, we calculate, collect, and remit various federal, state, and local taxes, fees and regulatory charges (“tax” or “taxes”) to numerous federal, state and local governmental authorities, including federal and state USF contributions and common carrier regulatory charges and public safety fees.
−Removed: In addition, we incur and pay state and local transaction taxes and fees on purchases of goods and services used in our business.
−Removed: Tax laws are dynamic and subject to change as new laws are passed and new interpretations of the law are issued or applied.
−Removed: In many cases, the application of existing, newly enacted or amended tax laws (such as the Coronavirus Aid, Relief, and Economic Security Act of 2020 or the U.S.
−Removed: Tax Cuts and Jobs Act of 2017) may be uncertain and subject to different interpretations, especially when evaluated against new technologies and telecommunications services, such as broadband internet access and cloud related services and in the context of our recent merger with Sprint.
−Removed: Legislative changes, administrative interpretations and judicial decisions affecting the scope or application of tax laws could also impact revenue reported and taxes due on tax inclusive plans.
−Removed: In the event that T-Mobile, including pre-acquisition Sprint, has incorrectly described, disclosed, determined, calculated, assessed, or remitted amounts that were due to governmental authorities, we could be subject to additional taxes, fines, penalties, or other adverse actions, which could materially impact our business, financial condition and operating results.
−Removed: In the event that federal, state, and/or local municipalities were to significantly increase taxes and regulatory or public safety charges on our network, operations, or services, or seek to impose new taxes or charges, such as a proposed corporate minimum tax or new limits on interest deductibility, it could have a material adverse effect on our business, financial condition and operating results.
+Added: As a result of the August 2021 cyberattack, we are subject to numerous claims, lawsuits and regulatory inquiries, the ongoing costs of which may be material, and we may be subject to further regulatory inquiries and private litigation.
+Added: For more information, see “– Contingencies and Litigation – Litigation and Regulatory Matters” in Note 11 – Commitments and Contingencies of the Notes to the Consolidated Financial Statements.” As a result of the August 2021 cyberattack, we may incur significant costs or experience other material financial impacts, which
+Added: may not be covered by, or may exceed the coverage limits of, our cyber insurance, and such costs and impacts may have a material adverse effect on our business, reputation, financial condition, cash flows and operating results.
+Added: In addition to the August 2021 cyberattack, we have experienced other unrelated immaterial incidents involving unauthorized access to certain Confidential Information.
+Added: Typically, these incidents have involved attempts to commit fraud by taking control of a customer’s phone line, often by using compromised credentials.
+Added: In other cases, the incidents have involved unauthorized access to certain of our customers’ private information, including credit card information, financial data, social security numbers or passwords, and to certain of our intellectual property.
+Added: Our procedures and safeguards to prevent unauthorized access to Confidential Information and to defend against cyberattacks seeking to disrupt our operations must be continually evaluated and enhanced to address the ever-evolving threat landscape and changing cybersecurity regulations.
+Added: These preventative actions require the investment of significant resources and management time and attention.
+Added: Additionally, we do not have control of the cybersecurity systems, breach prevention, and response protocols of our third-party providers.
+Added: While T-Mobile may have contractual rights to assess the effectiveness of many of our providers’ systems and protocols, we do not have the means to know or assess the effectiveness of all of our providers’ systems and controls at all times.
+Added: We cannot provide any assurances that actions taken by us, or our third-party providers will adequately repel a significant cyberattack or prevent or substantially mitigate the impacts of cybersecurity breaches or misuses of Confidential Information, unauthorized access to our networks or systems or exploits against third-party environments, or that we or our third-party providers, will be able to effectively identify, investigate, and remediate such incidents in a timely manner or at all.
+Added: We expect to continue to be the target of cyberattacks, given the nature of our business, and we expect the same with respect to our third-party providers.
+Added: Our inability to protect Confidential Information or to prevent operational disruptions from future cyberattacks may have a material adverse effect on our business, reputation, financial condition, cash flows, and operating results.
Unregistered Sales of Equity Securities and Use of Proceeds
1 unchanged sentence
Mine Safety Disclosures
+Added: Not applicable.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.