← Back to HAS filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
In connection with information set forth in this Quarterly Report on Form 10-Q, the risk factors discussed under Item 1A. Risk Factors, in Part I of our 2025 Form 10-K and in our subsequent filings, including in this filing, should be considered. The risks set forth in our 2025 Form 10-K and in our subsequent filings, including in this filing, could materially and adversely affect our business, financial condition, and results of operations. Except as set forth below, there are no material changes from the risk factors as previously disclosed in our 2025 Form 10-K, in any of our subsequently filed reports or as otherwise set forth in this Quarterly Report.
Our business could be significantly harmed as a result of compromise of our electronic data.
We and our third-party manufacturers and other business partners maintain significant amounts of data electronically in locations around the world and in the cloud. This data relates to all aspects of our business, including current and future products and entertainment under development, and also contains certain customer, consumer, supplier, partner and employee data. We and our partners maintain systems and processes designed to protect this data, but notwithstanding such protective systems and processes, there have been, and in the future may be, intrusions, cyber-attacks, tampering, or other unauthorized access, whether intentional or unintentional, that have compromised, and could in the future, compromise the integrity and privacy of this data. Intrusions, cyber-attacks, tampering, and other unauthorized access continue to increase in frequency, sophistication and intensity, and are becoming increasingly difficult to detect and prevent. They are often carried out by motivated, well-resourced, skilled and persistent actors, including nation states, organized crime groups, “hacktivists” and employees or contractors acting with malicious intent. Intrusions, cyber-attacks, tampering, and other unauthorized access could include the deployment of harmful malware and key loggers, ransomware, a denial-of-service attack, a malicious website, artificial intelligence, the use of social engineering and other means to affect the confidentiality, integrity and availability of our or third-party technology systems and data. Intrusions, cyber-attacks, tampering, and other unauthorized access could also include supply chain attacks, which could cause a delay in the manufacturing of our products. In addition, we provide confidential and proprietary information to our third-party manufacturers and business partners to conduct our business. While we obtain assurances from those parties that they have systems and processes in place to protect such data, and where applicable, that they will take steps to assure the
45
protections of such data by third parties, those manufacturers and partners may also be subject to data intrusion or otherwise compromise the protection of such data. The risk of data loss or breaches is heightened during uncertain economic times, changes in business strategy and reductions in workforce. Any compromise of the confidential data of our customers, consumers, suppliers, partners, employees or ourselves, or failure to prevent or mitigate the loss of or damage to this data through breach of our information technology systems, or those of our third party manufacturers and other business partners, as well as any related security incident response, containment, remediation, or mitigation efforts, could substantially disrupt our operations, result in delays of shipping products, result in delays in making or receiving payments, harm our customers, consumers, employees and other business partners, damage our reputation, violate applicable laws and regulations, subject us to potentially significant costs and liabilities and/or result in a loss of business that could be material.
For example, in late March 2026, we identified unauthorized access to our network. Upon discovery, we promptly activated our security incident response protocols, implemented containment measures, including proactively taking certain systems offline, and launched an investigation with the assistance of third-party cybersecurity professionals. As of June 28, 2026, the unauthorized access has been contained and the Company has fully restored our systems and returned to standard business operations.
Any further incidents of unauthorized access could result in adverse effects on our business, operations, financial results, and financial reporting; and any further impacts related to the unauthorized access or other similar unauthorized activity may result in increased costs, including from any legal proceedings. For more information, refer to Part I, Item 2. “Management’s Discussion and Analysis of Financial Condition and Results of Operation – Unauthorized Network Access” and Note 2 "Unauthorized Network Access."