In connection with our business, we and our service providers collect and retain large volumes of certain types of personal and proprietary information pertaining to our guests, shareholders, and employees. Such information includes, but is not limited to, large volumes of guest credit and payment card information, guest travel documents, other identification documents, account numbers, and other personally identifiable information. We are subject to attack by cyber-criminals operating on a global basis attempting to gain access to such information, and the integrity and protection of that guest, shareholder, and employee data is critical to us.
While we maintain what we believe are reasonable security controls over personal and proprietary information (including the personal information of guests, shareholders, and employees), breaches of or breakdowns in our systems that result in the theft, loss, fraudulent use or other unauthorized release of personal, confidential or other proprietary information, or other data have occurred in the past and may occur again in the future. In addition, any such cyber-attacks could persist for an extended period of time without detection, which could have a material adverse effect on our brands, reputation, business, financial condition and results of operations, as well as subject us to significant regulatory actions and fines, litigation, losses, third-party damages and other liabilities. Such a breach or a breakdown could also materially increase our costs to protect such information and to protect and insure against such risks. Our and our third-party service providers' vulnerability to attack exists in relation to known and unknown threats. As a consequence, the security measures we deploy are not perfect or impenetrable, and we may be unable to anticipate or prevent all unauthorized access attempts made on our systems or those of our third-party service providers.
Data breaches and other serious cyber incidents have increased globally, along with the methods, techniques and complexity of attacks, including use of viruses, ransomware and other malicious software, phishing and other efforts to discover and exploit any design flaws, bugs or other security vulnerabilities. Continued geopolitical turmoil (including the ongoing conflict between Russia and Ukraine and the ongoing conflict in the Middle East) has heightened the risk of cyber-attacks. We have experienced and likely will continue to experience, such cyber-attacks. Also, the same cyber security threats exist for the third parties with whom we interact and share information, and cyber-attacks on third parties which possess or use our customer, personnel and other information have in the past adversely impacted us in the same way as a direct cyber-attack on us. Additionally, we also currently have a hybrid work environment in which many corporate associates work both in the office and remotely on an ongoing basis. The increase in the number of our associates working remotely has increased certain risks to our business, including increased demand on our information technology resources and systems, and greater potential for phishing and other cybersecurity attacks.
While to date no such cyber-attacks have had, individually or in the aggregate, any known material adverse impact on our operations or financial results, we cannot guarantee that cyber-attacks have not gone generally undetected or without general recognition of magnitude or will not continue to occur in the future, any of which could materially adversely affect our brands, reputation, consumer confidence in us, costs, and profitability.
Our information technology infrastructure (including our, and our third-party service providers', information systems and legacy proprietary online reservation and management systems) has been and will likely continue to be vulnerable to system failures such as server malfunction or software or hardware failures, computer hacking, phishing attacks, user error, cyber-terrorism, loss of data, computer viruses, ransomware and malware installation, and other intentional or unintentional interference, negligence, fraud, misuse and other unauthorized attempts to access or interfere with these systems and our personal and proprietary information. In addition, as we continue to transition from our legacy systems to new, cloud-based technologies and other technology systems, we may continue to face issues that may negatively impact guests, other individuals and third parties. In addition, as we pursue new initiatives that are designed to improve our operations and cost structure, the expansion and implementation of new technologies and systems (including artificial intelligence ("AI") technologies) carries significant potential risks, including failure to operate as designed, potential loss of or corruption of information, changes in security processes, implementation delays, and disruption of operations. The increased scope and complexity of our information technology infrastructure and systems could contribute to the risk of future material security breaches or breakdowns, any of which could have a material adverse impact on our business, brands, reputation, and results of operations. Further, if we fail to assess and identify cybersecurity risks associated with acquisitions and new initiatives, we may become increasingly vulnerable to such risks.
Additionally, we are subject to federal, state, and international laws and regulations relating to the collection, use, retention, security and transfer of personally identifiable information and individual payment data. The information, security and privacy requirements imposed by such laws and regulations are constantly evolving and are becoming increasingly demanding in the U.S., both at the federal and state levels, and in other jurisdictions where we operate. Aspects of these laws and regulations, as well as their enforcement, remain unclear, and foreign laws and regulations are often more restrictive or burdensome than those in the U.S. Moreover, we have incurred and will likely continue to incur significant costs relating to compliance with these laws and regulations, including costs related to updating certain business practices and systems. Further, any changes to laws or regulations, including new restrictions or requirements applicable to our business, or an increase in enforcement of existing laws and regulations, such as restricting use or sharing of consumer data, including for marketing or advertising or limiting the use of, limiting our ability to provide certain consumer data to our customers, or otherwise regulating AI and machine learning (including the use of algorithms and automated processing), could expose us to additional costs and liability. In addition, should we violate or not comply with any applicable laws, regulations, contractual requirements relating to data security and privacy, or with our own privacy and security policies, either intentionally or unintentionally, or through the acts of intermediaries, it could have a material adverse effect on our brands, marketing, reputation, business, financial condition, and results of operations, as well as subject us to significant fines, litigation, losses, third-party damages and other liabilities.