Swvl's business involves the collection, storage, transmission and other processing of Swvl's users' personal and other sensitive data. An increasing number of organizations, including large online and off-line merchants and businesses, other large Internet companies, financial institutions and government institutions, have disclosed breaches of their information security systems and other information security incidents, some of which have involved sophisticated and highly targeted attacks. Because techniques used to obtain unauthorized access to or to sabotage information systems change frequently and may not be known until launched, Swvl may be unable to anticipate, detect or prevent these attacks. Swvl has previously experienced a data breach. In July 2020, unauthorized parties gained access to a Swvl database containing identifiable information of its riders by exploiting a breach in certain third-party software used by Swvl. While such breach has not had a material impact on Swvl's business or operations and Swvl has since implemented measures designed to restrict any similar data breach, unauthorized parties may in the future gain access to Swvl's systems or facilities through various means, including gaining unauthorized access into Swvl's systems or facilities or those of Swvl's service providers, partners or users on Swvl's platform, or attempting to fraudulently induce Swvl's employees, service providers, partners, users or others into disclosing rider names, passwords, payment card information or other sensitive information, which may in turn be used to access Swvl's information technology systems, or attempting to fraudulently induce Swvl's employees, partners or others into manipulating payment information, resulting in the fraudulent transfer of funds to criminal actors. In addition, users on Swvl's platform could have vulnerabilities on their own mobile devices that are entirely unrelated to Swvl's systems and platform, but could mistakenly attribute their own vulnerabilities to Swvl. Further, breaches experienced by other companies may also be leveraged against Swvl. For example, credential stuffing and ransomware attacks are becoming increasingly common, and sophisticated actors can mask their attacks, making them increasingly difficult to identify and prevent. Certain efforts may be state-sponsored or supported by significant financial and technological resources, making them even more difficult to detect.
Although Swvl has developed systems and processes that are designed to protect users' data, prevent data loss and prevent other privacy or security breaches, these measures cannot guarantee security. Swvl's information technology and infrastructure may be vulnerable to cyberattacks or security breaches, and third parties may be able to access Swvl's users' payment card data and other personal information that are accessible through those systems. Swvl is still a growing company and may not have sufficient dedicated personnel or internal oversight to detect, identify, and respond to all privacy or security incidents. Additionally, as Swvl expands its operations, including sharing data with third parties or continuing the work-from-home practices of its employees (including increased use of video conferencing), Swvl's exposure to cyberattacks or security breaches may increase. Further, employee error, malfeasance or other errors in the storage, use or transmission of personal information could result in an actual or perceived privacy or security breach or other security incident. Although Swvl has policies restricting the access to the personal information it stores, these policies may be breached or prove inadequate.
Any actual or perceived breach of privacy or security could interrupt Swvl's operations, result in Swvl's platform being unavailable, result in loss or improper disclosure of data, result in fraudulent transfer of funds, harm Swvl's reputation and brand, damage Swvl's relationships with strategic partners and third-party service providers, result in significant legal, regulatory and financial exposure and lead to loss of driver or rider confidence in, or decreased use of, Swvl's platform, any of which could adversely affect Swvl's business, financial condition and operating results. Any breach of privacy or security impacting any entities with which Swvl may share or disclose data could have similar effects. Further, any cyberattacks or security and privacy breaches directed at Swvl's competitors could reduce confidence in the ridesharing industry as a whole and, as a result, reduce confidence in Swvl.
Additionally, responding to any privacy or security breach, including defending against claims, investigations or litigation in connection with any privacy or security breach, regardless of their merit, could be costly and divert management's attention. Swvl does not currently maintain any insurance to cover security breaches and incidents or losses relating to its network systems or operations. As a result, the successful assertion of one or more large claims against Swvl could have an adverse effect on Swvl's reputation, brand, business, financial condition and operating results.