Loading...
Loading...
Latest 10-Q filed 10/30/2024 · Compared against 7/31/2024
Chat is set up on each filing report page.
Ask about this filing, its industry, or sector trends.
AI responses are generated from filing and peer context and may contain errors.
ITEM 1A. RISK FACTORS
We are supplementing Item 1A. Risk Factors in our Annual Report on Form 10-K for the year ended December 31, 2023, as filed with the Securities and Exchange Commission on February 21, 2024 (the Annual Report). The following risk factors should be read in conjunction with the risk factors set forth in that Annual Report.
|
|
|
Operational Risks | ||
The Security Incident has had, and may continue to have, numerous adverse effects on our business, results of operations, financial condition and cash flows.
As previously disclosed, on July 16, 2020, we contacted certain customers to inform them about the Security Incident, including that in May 2020 we discovered and stopped a ransomware attack. Prior to our successfully preventing the cybercriminal from blocking our system access and fully encrypting files, and ultimately expelling them from our system with no significant disruption to our operations, the cybercriminal removed a copy of a subset of data from our self-hosted environment that affected over 13,000 customers. Based on the nature of the incident, our research and third party (including law enforcement) investigation we believe that no data went beyond the cybercriminal, was or will be misused, or will be disseminated or otherwise made available publicly. However, our investigation into the Security Incident remains ongoing and may provide additional information.
To date, we have received approximately 260 specific requests from customers for reimbursement of expenses incurred by them related to the Security Incident, all of which have been fully resolved and closed or are inactive and are considered by us to have been abandoned by the customers. We have also received approximately 400 reservations of the right to seek expense recovery in the future from customers or their attorneys in the U.S., U.K. and Canada related to the Security Incident, none of which resulted in claims submitted to us and are considered by us to have been abandoned by the customers. We have also received notices of proposed claims on behalf of a number of U.K. data subjects, which we are reviewing. In addition, insurance companies representing various customers interests through subrogation claims have contacted us, and certain insurance companies have filed subrogation claims in court, of which threewo cases remain active and unresolved. In addition, presently, we are a defendant in putative consumer class action cases in U.S. federal courts (most of which have been consolidated under multi district litigation to a single federal court) and in Canadian courts alleging harm from the Security Incident. The plaintiffs in these cases, who generally purport to represent various classes of individual constituents of our customers, generally claim to have been harmed by alleged actions and/or omissions by us in connection with the Security Incident and assert a variety of common law and statutory claims seeking monetary damages, injunctive relief, costs and attorneys fees, and other related relief. On May 14, 2024, the Court issued a memorandum opinion and order (1) denying the multi district litigation plaintiffs' motion for class certification because of the plaintiffs' failure to meet their burden of proof as to ascertainability, (2) granting our motion to exclude the multi district litigation plaintiffs' expert on the issue of ascertainability, and (3) denying the multi district litigation plaintiffs' motion to exclude our expert on the issue of ascertainability. Further, the Court denied as moot all other pending motions. On May 28, 2024, the plaintiffs filed a petition for permission to appeal under Rule 23(f) of the Federal Rules of Civil Procedure with the Fourth Circuit Court of Appeals (the Fourth Circuit), and we subsequently filed an opposition to such petition. On July 30, 2024, the Fourth Circuit denied the plaintiffs' petition. This litigation remains ongoing. We are subject to pending governmental actions or investigations by the U.S. Department of Health and Human Services, the Office of the Australian Information Commissioner and the Office of the Privacy Commissioner of Canada. (See Note 9 to our unaudited, condensed consolidated financial statements included in this report for a more detailed description of the Security Incident and related matters.)
|
|
|
|
|
|
|
|
|
|
| |||||||
Blackbaud, Inc.
On March 9, 2023, the Company reached a settlement with the SEC in connection with the Security Incident that fully resolved the previously disclosed SEC investigation of the Security Incident.
|
|
|
|
|
|
|
|
|
Third Quarter 2024 Form 10-Q | 51 | |||||||
Blackbaud, Inc.
On October 5, 2023, the Company entered into separate, substantially similar Administrative Orders with each of 49 state Attorneys General and the District of Columbia in connection with the Security Incident which fully resolved the previously disclosed multi-state Civil Investigative Demand and the separate Civil Investigative Demand from the Office of the Indiana Attorney General relating to the Security Incident.
On May 20, 2024, the U.S. Federal Trade Commission (the "FTC") finalized an Order (the FTC Order) evidencing its settlement with us in connection with the Security Incident. As part of the FTC Order, we were not fined and were not otherwise required to make any payment. Furthermore, we agreed to the FTC Order without admitting or denying any of the FTCs allegations, except as expressly stated otherwise in the FTC Order. The settlement described in the FTC Order fully resolved the FTC investigation. For more information, see the form of proposed order that was furnished as Exhibit 99.2 to our Current Report on Form 8-K filed with the SEC on February 2, 2024 and is identical in substance to the final FTC Order, and in Note 11 to our audited consolidated financial statements contained in our Annual Report on Form 10-K filed with the SEC on February 21, 2024.
As previously disclosed, oOn June 13, 2024, we agreed to a Final Judgment and Permanent Injunction with the Attorney General of the State of California (the "FinalCalifornia Judgment") relating to the Security Incident. This settlement fully resolved the last remaining U.S. state attorney general investigation into the Security Incident. Under the terms of the settlement, we agreed to comply with applicable laws; not to make misleading statements related to our data protection, privacy, security, confidentiality, integrity, breach notification requirements, and similar matters; and to implement and improve certain cybersecurity programs and tools. The terms of the settlement with California are generally consistent with those to which we agreed in settling with the other 49 state Attorneys General and the District of Columbia on October 5, 2023, as discussed below. As part of the settlement, we also agreed to pay a total of $6.8 million to the State of California. This amount was fully accrued as a contingent liability in the Company's financial statements as of March 31, 2024 and June 30, 2024, and subsequently paid in the third quarter of 2024. By agreeing to the Final Judgment, Blackbaud has denied wrongdoing or liability of any kind. Nothing contained in the FinalCalifornia Judgment is intended to be, and shall not in any event be construed or deemed to be, an admission or concession or evidence of any liability or wrongdoing whatsoever on the part of Blackbaud or any fact or violation of law, rule, or regulation. For more information, see the Final Judgment and Permanent Injunction of the State of California, County of San Diego that was furnished as Exhibit 99.1 to our Current Report on Form 8-K filed with the SEC on June 14, 2024.
As noted above, the terms of the FinalCalifornia Judgment, FTC Order, the Attorneys General Administrative Orders and our settlement with the SEC require that we implement and maintain certain processes and programs and comply with certain legal requirements related to cybersecurity and data protection. Any future regulatory investigation or litigation settlements may also contain such requirements. Effectively implementing, monitoring and updating these requirements has been, and is expected to be expeover an extended period of time, expensive and time-consuming over an extended period. Our failure to do so in accordance with the terms of our agreements with FTC, the Attorneys General and with the SEC, and possibly others, could expose us to additional material liability under the terms of the Administrative Orders, the SEC settlement, or otherwise.
See Note 9 to our unaudited, condensed consolidated financial statements in this report for a more detailed description of the Security Incident and related matters.
We may be named as a party in additional lawsuits, other claims may be asserted by or on behalf of our customers or their constituents, and we may be subject to additional governmental inquires, requests or investigations. Responding to and resolving these current and any future lawsuits, claims and/or investigations could result in material remedial and other expenses that will not be covered by insurance. It is reasonably possible that our estimated or actual losses may change in the near term for those matters and be materially in excess of the amounts accrued. Certain governmental authorities are seeking to have imposed, and others may in the future impose, undertakings, injunctive relief, consent decrees, or other civil or criminal penalties, which could, among other things, have materially increased our data security costs or otherwise required us to alter how we operate our business, and could further do so in the future. Although we intend to defend ourselves vigorously against the claims asserted against us, we cannot predict the potential outcomes, cost and expenses associated with current and any future claims, lawsuits, inquiries and investigations.
In addition, any legislative or regulatory changes adopted in reaction to the Security Incident or other companies data breaches could require us to make modifications to the operation of our business that could have an adverse effect and/or increase or accelerate our compliance costs.
|
|
|
|
|
|
|
|
|
|
| |||||||
Blackbaud, Inc.
Significant management time and Company resources have been, and are expected to continue to be, devoted to the Security Incident. For example, for the three and sixnine months ended JuneSeptember 30, 2024, we incurred net pre-tax expenses of $12.8 million and $12.1 million, respectively, relrelated to the Security Incident, which included $1.86.0 million and $5.1 million, respectively, for ongoing legal fees and additional accruals for loss
|
|
|
|
|
|
|
|
|
52 | Third Quarter 2024 Form 10-Q | |||||||
Blackbaud, Inc.
contingencies of $0.06.8 million and $7.0 million, respectively. . During the sixnine months ended JuneSeptember 30, 2024, we had cash outlays of $5.815.1 million related to the Security Incident for ongoing legal fees. and the $6.8 million paid during the third quarter of 2024 related to our settlement with the Attorney General of the State of California. For full year 2023, we currently expect pre-tax expenses of approximately $5.0 million to $10.0 million and cash outlays of approximately $8.0 million to $13.0 million for ongoing legal fees related to the Security Incident. Although we carry insurance against certain losses related to the Security Incident, we exceeded the limit of that insurance coverage in the first quarter of 2022. As a result, we will be responsible for all expenses or other losses (including penalties, fines or other judgments) or all types of claims that may arise in connection with the Security Incident, which could materially and adversely affect our liquidity and results of operations. (See Note 9 to our unaudited, condensed consolidated financial statements in this report.) If any such fines or , penalties or judgments were great enough that we could not pay them through funds generated from operating activities and/or cause a default under the 2024 Credit Facilities, we may be forced to renegotiate or obtain a waiver under the 2024 Credit Facilities and/or seek additional debt or equity financing. Such renegotiation or financing may not be available on acceptable terms, or at all. In these circumstances, if we were unable to obtain sufficient financing, we may not be able to meet our obligations as they come due.
In addition, publicity or developments related to the Security Incident could in the future have a range of other adverse effects on our business or prospects, including causing or contributing to loss of customer confidence, reduced customer demand, reduced customer retention, strategic growth opportunities, and associated retention and recruiting difficulties, some or all of which could be material.
Defects, delays or interruptions in our cloud solutions, hosting services and payment services, including those caused by our vendors, partners or other third parties (such as the CrowdStrike Event described below), could diminish demand for these services and subject us to substantial liability.
We utilize data center hosting facilities to provide cloud solutions to a significant number of our subscription customers, hosting services to our on-premise license customers and transactional payment services. Any damage to, or failure of, these systems or services generally could result in, and have resulted in (as described below), interruptions in service to our customers, notwithstanding any business continuity or disaster recovery agreements or arrangements that may be in place. Our executive offices and some of our data centers are located in areas that are vulnerable to the effects of climate change and could be subject to increased interruptions as a result of the severity and increased frequency of extreme weather events such as hurricanes, wildfires, floods, heat waves, or power shortages. Furthermore, because our cloud solutions, hosting service offerings and payment services are complex and incorporate a variety of computer hardware and software systems, our services have in the past developed, and may again develop, errors or defects, whether of our own creation or caused by third parties, that have, and could again, result in unanticipated downtime or other problems for our customers and us. Internet-based services sometimes contain undetected errors when first introduced or when new versions or enhancements are released. We have from time to time found defects in our web-based services and new errors might again be detected in the future. In addition, our customers might use our Internet-based offerings in unanticipated ways that cause a disruption in service for other customers attempting to access their data.
For example, on July 19, 2024, CrowdStrike Holdings, Inc. (CrowdStrike), which provides cybersecurity services to millions of Microsoft Windows systems worldwide, including to certain Windows systems operated by Blackbaud, implemented a software update to its Falcon sensor software that was flawed and caused Falcon to crash, thereby causing widespread crashes of Windows systems into which it was integrated, including certain Windows systems used by us and certain of our customers (the CrowdStrike Event). As a result, some of our customers were unable to access certain of our services and solutions, including our payments processing solutions. We are still evaluating the actual and potential impact of the CrowdStrike Event on Blackbaud, both directly and indirectly due to the impact on our customers.
Because our customers use our services for important aspects of their businesses, any defects, delays or disruptions in service or other performance problems with our services, such as the CrowdStrike Event, could hurt our reputation, damage our customers' businesses and result in liability for the Company. For example, customers could elect to cancel their service, delay or withhold payment to us, not purchase from us in the future or make claims against us, which could result in an increase in our provision for credit losses, an increase in collection cycles for accounts receivable, loss of revenue or the expense and risk of litigation. Any of these could materially harm our business, reputation, financial condition and results of operations.
|
|
|
|
|
|
|
|
|
|
| |||||||
Blackbaud, Inc.
|
|
|
| ||
We significantly increased our leverage in connection with acquisition of EVERFI and stock repurchases, and may increase our leverage in the future in connection with additional acquisitions, Security Incident costs or other business purposes, which could adversely impact our business and financial performance.
We incurred a substantial amount of indebtedness in connection with acquisitions, including our acquisition of EVERFI, Inc. (as described in Note 3 in our most recently filed Annual Report on Form 10-K). As a result of this indebtedness and other borrowings, including our borrowings in March 2024 to fund the ASR Transaction, our interest payment obligations have increased. In addition, we have been named as a party in various lawsuits in connection with the Security Incident, claims have been asserted by or on behalf of our customers or their constituents, and we are subject to various governmental inquires, requests or investigations. Responding to and resolving these current and any future lawsuits, claims and/or investigations could result in material remedial and other expenses. Although we intend to defend ourselves vigorously against the claims asserted against us, we cannot predict the potential outcomes, cost and expenses associated with current and any future claims, lawsuits, inquiries and investigations, which could require that we incur additional indebtedness to fund. (See Note 9 to our unaudited, condensed consolidated financial statements in this report for additional information regarding the Security Incident.)
The degree to which we are leveraged could have adverse effects on our business, including the following:
Requiring us to dedicate a substantial portion of our cash flow from operations to payments on our indebtedness, thereby reducing the availability of our cash flow to fund working capital, capital expenditures, acquisitions, dividends, stock repurchases and other general corporate purposes;
Increasing the amount of interest we pay, particularly if interest rates increase;
Limiting our flexibility in planning for, or reacting to, changes in our business and the industries in which we operate;
Restricting us from making additional strategic acquisitions or exploiting business opportunities;
Placing us at a competitive disadvantage compared to our competitors that have less debt;
Reducing our currently available borrowing capacity or limiting our ability to borrow additional funds; and
Decreasing our ability to compete effectively or operate successfully under adverse economic and industry conditions.
If we incur additional debt, these risks may intensify. Our ability to meet our debt service obligations will depend upon our future performance, which will be subject to the financial, business and other factors affecting our operations, many of which are beyond our control.
In addition, additional leverage could impact our ability to meet certain financial and other covenants contained in our 2024 Credit Facilities, which increased our total borrowing capacity from $1.1 billion to $1.5 billion. (See Note 7 to our unaudited, condensed consolidated financial statements included in this report for a more detailed description of our 2024 Credit Facilities.) There can be no assurance that we will be able to remain in compliance with the covenants to which we are now subject or may be subject in the future and, if we fail to do so, that we will be able to obtain waivers from our lenders or amend the covenants.
In the event of a default under our 2024 Credit Facilities, we could be required to immediately repay all outstanding borrowings, which we might not be able to do and which would materially negatively affect our business, operations and financial condition.
|
|
|
|
|
|
|
|
|
|
| |||||||
Blackbaud, Inc.