Loading...
Loading...
Chat is set up on each filing report page.
Ask about this filing, its industry, or sector trends.
AI responses are generated from filing and peer context and may contain errors.
Item 1A. Risk Factors
In addition to the other information set forth in this report, you should carefully consider the factors discussed in Part I, Item 1A. Risk Factors in our Annual Report on Form 10-K for fiscal year 2025, which could materially affect our business, financial condition, and/or future results. The risks described in our Annual Report on Form 10-K are not the only risks we face. Additional risks and uncertainties not currently known to us or that we currently deem to be immaterial also may materially adversely affect our business, financial condition, and/or operating results. There have been no material changes to the risk factors set forth in our Annualnd in Part II, Item 1A. Risk Factors in our Quarterly Report on Form 10-KQ for fiscal year 2025 as filed with the SEC on February 1the quarter ended March 28, 2026, except as disclosed below.
We have in the past experienced and in the future (Q1 10-Q) which could experience unauthorized access into our information systems.
We operate large and complex information systems that contain significant amounts of client data. As a routine element of oumaterially affect our business, we collect, analyze and retain substantial amounts of data pertaining to the non-clinical studies we conduct for our clients. Unauthorized third parties could attempt to gain entry to such information systems to steal data or disrupt the systems or for financial gain. Like other companies, we have on occasion experienced, and will continue to experience, threats and incursions to our data and systems, including malicious software and viruses, phishing, business email compromise and social engineering attacks, network intrusions, or other cyber-attacks. The number and complexity of these threats continue to increase over time. These threats also may be further enhancefinancial condition, and/or future results. The risks described in frequency or effectiveness through threat actors use of artificial intelligence technologies, which are becoming more widely adopted aour 2025 Form 10-K and increasingly sophisticated.
In response to past cybersecurity incidents, we have implemented additional security safeguards and continually work to enhance existing safeguards; however, such efforts may not be successful, in which case we could suffer significant harm.
35
CH our Q1 10-Q are not the only risks we face. ARLES RIVER LABORATORIES INTERNATIONAL, INC.
We are at risk of being targeted, and we have in the past been victim to, business email compromise fraud, which results in payments being made to illegitimate bank accounts. Although these instances have not resulted in our incurring material losses, if similar instances occur in the future, we may incur such losses.
We have recently become aware of unauthorized access to certain information systems of the Company. The incident involved a social engineering attack in which a threat actor impersonated a trusted party and obtained employee access credentials from a small number of employees. We identified the incident and immediately activated our cyber incident response plan to contain the intrusion, assess and investigate the incident and implement remedial measures. Based on the information reviewed to date, we believe the unauthorized activity has been contained and did not result in any material disruption to our information systems. We are currently in the process of ascertaining what, if any, information was exfiltrated, including whether there was any compromise of sensitive and/or personal identifiable information contained within the accessed information systems. As of the date hereof, the Company believes that this cybersecurity incident has not had a material impact on the Companys financial systems, operations or financial condition due in part to the Companys previously implemented security safeguards.
As a result of this or any cybersecurity incident, we may be subject to business disruptions or governmental investigations, private litigation or other claims, which could result in fines, other monetary relief, or injunctive relief that could materially increase our data security costs, adversely impact how we operate our systems and collect and use personal infordditional risks and uncertainties not currently known to us or that we currently deem to be immaterial also may mation. If, as a result of any such governmental investigation, other investigation or claim, we are found to be in violation of applicable laws and regulations including, without limitation, anerially applicable data privacy and information security laws or regulations, we could be subject to legal risk, including governmental enforcement action and civil litigation, which could adverseldversely affect our business, reputation, financial condition or results of operations. Defending any such litigation claim or enforcement action, regardless of merit, and whether successful , and/or unsuccessful, and coooperating with regulatory investigations, could be expensive and time-consuming and adversely affect our business, reputation, results of operations or financial condition. In addition, we may be adversely impacted by reputational harm or a loss of confidence in the security anresults. Except for the risk factor disclosed integrity of our information systems among customers Part II, Item 1A of the Q1 10-Q, employees and business partners. There can be no assurance, however, that this cybersecurity incident or any future cybersecurity incidents will not have a material impact on the Companys future operations, financial systems or financial condition.
We leverage software and hardware solutions from technology and services providers, including software-as-a-service and public cloud infrastructure, who have been subject to cybersecurity incidents in the past and may have incidents or breaches in the future. As of the date of this filing, to our knowledge, no prior cybersecuritywhich is hereby incorporated by reference incident or breach at a third party has had a material impact on our business. However, future incidents or breaches could cause us to suffer significant harm.
Our contracts with our clients typically contain provisions that require us to keep confidentialto this Part II, Item 1A of the information generated from the studies we conduct. In the event the confidentiality of such information is compromised, wheis Form 10-Q, ther by unauthorized access or other breaches, we could be exposed to significant harm, including termination of customer contracts, damage to our customer relationships, damage to our reputation and potential legal claims from customers, employees and other parties. In addition, we may face investigations by government regulators and agencies as a result of a breach.
Additionally, te have been no material changes to the rapid ongoing evolution and increased adoption of emerging technologies such as artificial intelligence and machine learning may make it more difficult to anticipate and implement protective measures to recognize, detect, and prevent the occurrence of any of Companys risk factors since the cyber events described above.
2025 For information regarding our processes and practices related to information and cybersecurity, please see our Annual Report on Form m 10-K for.
43
CHARLES fiscal year 2025 as filed with the SEC on February 18, 2026, specifically Section 1C CybersecurityRIVER LABORATORIES INTERNATIONAL, INC.