← Back to MMI filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
Except as set forth below, there have been no material changes from the risk factors described in our Annual Report on Form 10-K for the year ended December 31, 2025.
We have been subject to cybersecurity incidents in the past and may be the target of future attacks. The failure to maintain the security of our information and technology networks, including personally identifiable and client information, could adversely affect us.
Security breaches and other disruptions could compromise our and our clients' information and expose us to liability, which could cause our business and reputation to suffer. In the ordinary course of our business, we collect and store sensitive data, including our proprietary business information and intellectual property and that of our clients and personally identifiable information of our employees and contractors, in third-party data centers and on our networks. The secure processing, maintenance and transmission of this information is critical to our operations. Our information technology and infrastructure have been subject to, and may in the future be vulnerable to various cyber-attacks, such as hacking, spoofing and phishing attacks and ransomware attacks, exploitation of system or application vulnerabilities or our systems may be breached due to employee error, malfeasance or other disruptions. We may also not have sufficient logs available to fully investigate the scope of a cyber-attack.
In April 2026, the Company experienced a cybersecurity incident in which a threat actor used social engineering techniques to obtain an employee's login credentials and gain unauthorized access to certain Company systems, resulting in the exfiltration of certain customer, employee, and internal business data. The Company promptly detected the incident, contained the unauthorized access, and engaged outside cybersecurity and legal counsel to assist with its response. The Company's systems and business operations were not disrupted, and the Company does not believe the incident has had a material impact on its business, financial condition or results of operations. There can be no assurance that future cybersecurity incidents will not adversely affect our reputation, brand, business, financial condition, and results of operations, or result in future costs, litigation, or regulatory proceedings.
45