← Back to ADI filing summaryThis is the extracted source text from the SEC filing. Formatting may differ from the original document.
We are subject to a number of risks that could adversely affect our business, results of operations, financial condition and future prospects, including those identified in Part I, Item 1A, “Risk Factors” of our Annual Report on Form 10-K for the fiscal year ended November 1, 2025, which was filed with the Securities and Exchange Commission on November 25, 2025 (the 2025 Form 10-K). Except for the risk factor set forth below, there have been no material changes from the factors disclosed in the 2025 Form 10-K.
Our computer systems and networks are subject to security breaches and other cyber incidents and a significant disruption in, or breach in security of, our information technology systems or certain products could materially and adversely affect our business or reputation.
We rely on information technology systems throughout our company to keep financial records and customer data, process orders, manage inventory, coordinate shipments to customers, maintain confidential and proprietary information, assist in semiconductor engineering and other technical activities and operate other critical functions such as internet connectivity, network communications and email. In addition, we provide our confidential and proprietary information to our strategic partners in certain cases, who maintain such information on their information technology systems. We have experienced cybersecurity attacks and incidents, such as the June 2026 incident and other cybersecurity events, some of which resulted in the exfiltration of files from certain affected systems. While our operations were not interrupted as a result of the June 2026 incident, and based on information currently known, we do not believe this incident is reasonably likely to materially impact our business, operations, or financial condition, our investigation into the nature and scope of the exfiltrated information remains ongoing. There is no assurance that our assessment will not change as additional facts emerge, that exfiltrated data will not be misused, or that we will not experience additional incidents in the future that may have a material impact on our business. As demonstrated by the June 2026 incident and other cybersecurity events, our security measures and those of our third-party service providers and strategic partners may not detect or prevent all security breaches, cyberattacks, defects, bugs or errors, and threat actors can be successful in gaining unauthorized access to our systems. We expect that we and our third-party service providers and strategic partners will continue to experience cybersecurity attacks and incidents in the future.
Geopolitical tensions and conflicts have escalated the volume and sophistication of cyberattacks. Because the tactics and techniques used by threat actors to obtain unauthorized access to or sabotage systems change frequently and, in some cases, are not recognized until they are launched or even later, we are unable to anticipate all such techniques and may not be able to implement adequate preventative measures in advance, such that security breaches could remain undetected for extended periods of time. Our use of artificial intelligence (AI) can also increase vulnerability to cybersecurity risks, including through unauthorized use or misuse of AI tools and bad inputs or logic or the introduction of malicious code incorporated into AI generated code. AI and machine learning are also used in certain cybersecurity attacks, improving or expanding the existing capabilities of threat actors in ways that can result in greater risks of security incidents and breaches.
We and our third-party service providers and strategic partners are subject to security breaches of information technology systems and certain products and other incidents such as unauthorized access, supply-chain attacks, exfiltration or destruction of data, disruption of service, viruses or other malicious code, illegal break-ins or hacking, sabotage, phishing attempts and other forms of social engineering, malware, ransomware and other forms of cyber extortion and similar events. These threats come from cybercriminals, cyberterrorists and hacktivists, nation-state and nation-state-supported actors (including advanced persistent threat intrusions) and computer hackers. They also can result from the malicious or accidental acts of our employees, contractors or third-party providers. Unauthorized access to, or a security breach of, our systems or those of our third-party service providers or strategic partners could disrupt our operations. As occurred in the June 2026 incident, such events can result in the exfiltration of data from our systems and could expose our proprietary information or that of our employees, contractors, partners, customers, suppliers or other third parties to misappropriation or misuse. In the event of a cybersecurity attack or incident such as the June 2026 incident, we may become subject to litigation and regulatory action, lose existing or potential customers, suffer reputational damage and incur other financial losses. We have incurred and expect to continue to incur costs in connection with our response to and remediation of cybersecurity incidents, and such costs and operational consequences may be significant. The continuing and evolving threat of cyberattacks has resulted in increased regulatory focus which requires us to invest significant additional resources to comply with evolving cybersecurity regulations. In addition, in 2023, the SEC adopted rules requiring an issuer to disclose whether a cybersecurity incident was determined to be "material," within four business days of such determination. Making such determinations is complex, requires a number of assumptions based on several factors, and must be made while investigations may still be ongoing and the full scope of an incident may not yet be known. The SEC may not agree with our determinations regarding the materiality of cybersecurity incidents, which could result in fines, civil litigation or damage to our reputation. In addition, certain incidents may require us to notify affected
24
parties and applicable regulators in accordance with applicable law, and we may face regulatory scrutiny regarding the timeliness or adequacy of such notifications.
Our information technology systems and those of our third-party service providers and strategic partners are also susceptible to damage, disruptions or shutdowns due to power outages, hardware failures, telecommunication failures, user errors, catastrophes or other unforeseen events. A prolonged disruption in the information technology systems that involve our internal communications or our interactions with customers or suppliers could result in the loss of sales and customers and significant incremental costs, which may adversely affect our business.