bank partners and third-party vendors’ and/or other business partners’ information technology systems or other similar data security incidents could adversely affect our business operations and result in the loss, misappropriation, or unauthorized access, use or disclosure of, or the prevention of access to, sensitive information, which could result in financial, legal, regulatory, business and reputational harm to us.
Because techniques used to obtain unauthorized access or to sabotage systems change frequently and generally are not recognized until they are launched against a target, we and our vendors may be unable to anticipate these techniques or to implement adequate preventative measures. In addition, many governments have enacted laws requiring companies to notify individuals of data security breaches involving their personal data. These mandatory disclosures regarding a security breach are costly to implement and often lead to widespread negative publicity following a breach, which may cause borrowers and potential borrowers to lose confidence in the effectiveness of our data security measures on our platform. Any security breach, whether actual or perceived, would harm our reputation and ability to attract new borrowers to our platform.
We also face indirect technology, cybersecurity and operational risks relating to the borrowers, bank partners, investors, vendors and other third parties with whom we do business or upon whom we rely to facilitate or enable our business activities, including vendors, payment processors, and other parties who have access to confidential information due to our agreements with them. In addition, any security compromise in our industry, whether actual or perceived, or information technology system disruptions, whether from attacks on our technology environment or from computer malware, natural disasters, terrorism, war and telecommunication and electrical failures, could interrupt our business or operations, harm our reputation, erode borrower confidence, negatively affect our ability to attract new borrowers, or subject us to third-party lawsuits, regulatory fines or other action or liability, which could adversely affect our business and results of operations.
Like other financial services firms, we have been and continue to be the subject of actual or attempted unauthorized access, mishandling or misuse of information, computer viruses or malware, and cyber-attacks that could obtain confidential information, destroy data, disrupt or degrade service, sabotage systems or cause other damage, distributed denial of service attacks, data breaches and other infiltration, exfiltration or other similar events.
While we regularly monitor data flow inside and outside the company, attackers have become very sophisticated in the way they conceal access to systems, and we may not be aware that we have been attacked. Any event that leads to unauthorized access, use or disclosure of personal information or other sensitive information that we or our vendors maintain, including our own proprietary business information and sensitive information such as personal information regarding borrowers, loan applicants or employees, could disrupt our business, harm our reputation, compel us to comply with applicable federal and/or state breach notification laws and foreign law equivalents, subject us to time consuming, distracting and expensive litigation, regulatory investigation and oversight, mandatory corrective action, require us to verify the correctness of database contents, or otherwise subject us to liability under laws, regulations and contractual obligations, including those that protect the privacy and security of personal information. This could result in increased costs to us and result in significant legal and financial exposure and/or reputational harm. In addition, any failure or perceived failure by us or our vendors to comply with our privacy, confidentiality or data security-related legal or other obligations to our bank partners or other third parties, actual or perceived security breaches, or any security incidents or other events that result in the unauthorized access, release or transfer of sensitive information, which could include personally identifiable information, may result in governmental investigations, enforcement actions, regulatory fines, litigation, or public statements against us by advocacy groups or others, and could cause our bank partners and other third parties to lose trust in us or we could be subject to claims by our bank partners and other third parties that we have breached
34