Item 1A. Risk factors The risks described in Risk factors in our Annual Report on Form 10-K for the fiscal year ended January 31, 2024 , this Quarterly Report on Form 10-Q, and subsequent periodic reports could materially and adversely affect our business, financial condition and results of operations. There have been no material changes in such risks. These risk factors do not identify all risks that we face, and our operations could also be affected by factors that are not presently known to us or that we currently consider to be immaterial to our operations. Cyber-attacks, including ransomware attacks, or other privacy or data security incidents could materially adversely impact our business. Our proprietary technology platforms enable the exchange of, and access to, sensitive information, and, as a result, we are frequently the target of cyber-attacks or other privacy or data security incidents. As one of the largest providers of HSAs and other CDBs, we are an attractive target for cyber-attacks, including ransomware attacks, which means we must continue to secure and monitor each of our technology platforms, making sure these platforms are aligned to our industry benchmark security posture. In addition, geopolitical events, including the war between Russia and Ukraine, have resulted in, and may continue to result in, an increase in cyber-attacks. Substantially all of our workforce works remotely. This remote work environment increases the risk of cybersecurity breaches and incidents, and the potential impact of these on our operations is also higher while our team members log into our network remotely. In addition, we use third-party operations partners to service our members. These third-party partners have access to member information in order to provide this service, which further increases the risk of cybersecurity breaches and incidents through those partners. Our ability to ensure the security of our technology platforms and thus sensitive customer and partner information is critical to our operations. We rely on standard Internet and other security systems to provide the security and authentication necessary to effect secure transmission of data. Despite our security measures, our information technology and infrastructure are vulnerable to cybersecurity threats, including attacks by hackers and other malfeasance. Such security breaches could compromise our networks, or those of third-party service providers on which we rely, and result in the information stored or transmitted there to be accessed, modified or used in an unauthorized manner, publicly disclosed, lost, or stolen. Such access, use, disclosure, or other loss of information could result in regulatory scrutiny, legal claims or proceedings leading to liability, including under laws that protect the privacy of personal information, disrupt our operations and the services we provide to our Clients, damage our reputation, and cause a loss of confidence in our products and services, which could adversely affect our business, operations, and competitive position. Security breaches, including a major breach of our network security and systems, could result in serious negative consequences for our business, including the loss of sensitive information, theft or loss of actual funds, litigation, indemnity obligations to our Clients, fines, penalties and other liabilities, including under laws that protect the privacy of personal information, disrupt our operations and the services we provide to our members, Clients and Network Partners. Such breaches could damage our reputation and cause a loss of confidence in our products and services, reducing demand and resulting in an unwillingness of members, Clients, Network Partners and other data owners to provide us with their payment information or personal information, and otherwise harm our brand. Furthermore, if third parties improperly obtain and use the personal information of our members, we may be required to expend significant resources to resolve these problems. While we have security measures in place, we have experienced data privacy incidents in the past, including an incident earlier this year in which a business partner's user account containing personally identifiable information was breached, in addition to several incidents in 2018. As a result of the incident earlier this year, we are now subject to several putative class action lawsuits seeking unspecified damages, and we expect to be subject to -38- regulatory investigations related to the incident. Whether as a result of these incidents, or if our security measures are breached again or unauthorized access to data is otherwise obtained as a result of third-party action, team member error or otherwise, our reputation could be significantly damaged, our business may suffer and we could incur substantial liability, which could result in loss of sales, Clients and Network Partners. Because techniques used to obtain unauthorized access to or sabotage systems change frequently and such novel techniques may not be identified until they are launched against a target, we may be unable to anticipate, or to implement adequate preventative measures to address, these techniques. Any or all of these issues could negatively impact our ability to attract new, or increase engagement by, members, Clients and Network Partners, and subject us to third-party lawsuits, regulatory fines, contractual liability, and other action or liability, thereby harming our operating results or financial condition.