Our business involves the collection, processing, transmission and storage of customers' personal and confidential information, including dates of birth, banking information, credit and debit card information, data we receive from consumer reporting companies, including credit report information, as well as confidential information about our retail partners and employees, among others. Much of this data constitutes confidential personally identifiable information ("PII") which, if unlawfully accessed, either through a "hacking" attack or otherwise, could subject us to significant liabilities as further discussed below. Companies like us that possess significant amounts of PII and/or other confidential information have experienced a significant increase in cyber security risks in recent years from increasingly aggressive and sophisticated cyberattacks, including hacking, computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing and impersonation), denial-of-service attacks and other attacks and similar disruptions from the unauthorized use of or access to information technology ("IT") systems. Our IT systems are subject to constant attempts to gain unauthorized access in order to disrupt our business operations and capture, destroy or manipulate various types of information that we rely on, including PII and/or other confidential information. In addition, various third parties, including employees, contractors or others with whom we do business may attempt to circumvent our security measures in order to obtain such information, or inadvertently cause a breach involving such information. Any significant compromise or breach of our data security, whether external or internal, or misuse of PII and/or other confidential information may result in significant costs, litigation and regulatory enforcement actions and, therefore, may have a material adverse impact on our business, operating results and financial condition. Further, if any such compromise, breach or misuse is not detected quickly, the effect could be compounded. While we have implemented network security systems and processes to protect against unauthorized access to or use of secured data and to prevent data loss and theft, there is no guarantee that these procedures are adequate to safeguard against all data security breaches or misuse of the data. We maintain private liability insurance intended to help mitigate the financial risks of such incidents, but there can be no guarantee that insurance will be sufficient to cover all losses related to such incidents, and our exposure resulting from any serious unauthorized access to, or use of, secured data, or serious data loss or theft, could far exceed the limits of our insurance coverage for such events. Further, a significant compromise of PII and/or other confidential information could result in regulatory penalties and harm our reputation with our customers, retail partners and others, potentially resulting in a material adverse impact on our business, operating results and financial condition. The regulatory environment related to information security, data collection and use, and privacy is increasingly rigorous, with new and constantly changing requirements applicable to our business, and compliance with those requirements could result in additional costs. We also believe successful data breaches or cybersecurity incidents at other companies, whether or not we are involved, could lead to a general loss of customer confidence that could negatively affect us, including harming the market perception of the effectiveness of our security measures or financial technology in general. We believe our exposure to this risk will increase as we expand our use of financial technology to communicate with our customers and retail partners and as we increase the number of retail partners with whom we work.