Loading...
Loading...
Chat is set up on each filing report page.
Ask about this filing, its industry, or sector trends.
AI responses are generated from filing and peer context and may contain errors.
Item 1A. Risk Factors
There have been no material changes from the risk factors previously disclosed in Part I, Item 1A of the Companys Form 10-K for the year ended December 31, 2025, filed with the Commission on March 31, 2026 (the Form 10-K), under the heading Risk Factors, aexcept as discussed below, and investors should review the risks provided in the Form 10-K and below, prior to making an investment in the Company. The business, financial condition and operating results of the Company can be affected by a number of factors, whether currently known or unknown, including but not limited to those described in the Form 10-K, under Risk Factors and below, any one or more of which could, directly or indirectly, cause the Companys actual financial condition and operating results to vary materially from past, or from anticipated future, financial conditions and operating results. Any of these factors, in whole or in part, could materially and adversely affect the Companys business, financial condition, operating results and stock price.
Failures, disruptions, defects or errors in our internally developed software and technology infrastructure could harm our business, reputation and results of operations.
Our online casino and sports wagering platforms depend on the continuous, reliable operation of complex, internally developed and proprietary software, as well as the underlying technology infrastructure, including servers, databases, cloud hosting environments, networks, and related systems, that together support real-time wagering, account management, payment processing, and responsible gaming controls. This software and infrastructure may contain undetected errors, bugs, or design defects, particularly as we update existing platforms, deploy new features, integrate acquired technology, or scale to accommodate increased user volume or new jurisdictions. Any such defects, or any failure, outage, or degradation in performance of our systems, whether caused by software errors, hardware failures, capacity constraints, power outages, natural disasters, human error, or other causes, could result in incorrect bet settlement, erroneous odds or payouts, inability of customers to place or settle wagers, or extended service interruptions, particularly during high-traffic periods such as major sporting events. Any of the foregoing could result in customer dissatisfaction and attrition, negative publicity, regulatory scrutiny or enforcement action, litigation, financial losses (including losses arising from mispriced or mis-settled wagers), and harm to our brand and competitive position, any of which could materially and adversely affect our business, financial condition, and results of operations.
|
66 |
|
|
We rely on third-party systems, platform providers, and content providers to operate our business, and any failure, disruption, or deterioration in these relationships or systems could materially harm our operations.
We depend on a variety of third parties to operate our online casino and sports betting products, including third-party gaming platform and content providers, payment processors and banking partners, cloud hosting and content-delivery providers, geolocation and identity-verification vendors, and other technology and service providers. We do not fully control the operation, security, or reliability of these third-party systems. If any of these providers experiences an outage, service degradation, security breach, financial distress, insolvency, or termination of its relationship with us, or if we are unable to renew agreements with key providers on commercially reasonable terms (or at all), we may be unable to offer affected games or services, may experience delayed or interrupted service to our customers, and may be required to transition to alternative providers on short notice, which could be costly, time-consuming, and disruptive. Certain of our third-party providers may also be single points of failure for particular products or markets, increasing our exposure to any disruption of their systems. Any of these events could result in loss of customers and revenue, reputational harm, and regulatory consequences, and could materially and adversely affect our business and results of operations.
We depend on external data feeds, including sports event and odds data, and any inaccuracy, delay, or interruption in this data could result in improper bet settlement, financial losses, and regulatory exposure.
Our sports wagering operations depend on data feeds licensed from third-party data providers for real-time sports scores, statistics, event outcomes, and in certain situations, pricing/odds information, which we use to offer markets, price wagers, and settle bets. We also rely on external data and content feeds to support certain online casino products. If these data feeds are delayed, interrupted, inaccurate, incomplete, or manipulated (whether due to technical failure, provider error, loss of a data licensing relationship, or other causes), we may be unable to offer or may be forced to suspend certain betting markets, may settle wagers incorrectly, or may be exposed to arbitrage or advantage betting by customers exploiting stale or erroneous data. Errors in official event data can also lead to disputes with customers over bet settlement, potential financial liability, negative publicity, and regulatory inquiries or sanctions in jurisdictions that impose specific integrity or data-accuracy requirements on licensed operators. Any loss of access to reliable, timely sports data, or a material increase in the cost of licensing such data, could impair our ability to compete effectively and could materially and adversely affect our business and results of operations.
Cybersecurity incidents, hacking, or other technology-related attacks against us or our third-party providers could disrupt our operations, compromise sensitive data, and expose us to significant liability and reputational harm.
Our business involves the collection, storage, and processing of large volumes of sensitive customer information, including personal, financial, and payment data, as well as proprietary business and wagering data. Our systems, and the systems of the third parties on which we rely, are targets for cyberattacks, including hacking, ransomware, denial-of-service attacks, phishing and social engineering, credential-stuffing and account takeover attempts, malware, and other efforts by increasingly sophisticated bad actors, including organized groups seeking to defraud our platform or manipulate wagering outcomes. Despite our investment in security controls, we may not be able to anticipate, detect, or prevent all such attempts, and a successful cybersecurity incident could result in unauthorized access to or disclosure, loss, or misuse of customer or company data; theft of funds; manipulation or corruption of wagering, payout, or account data; extended platform outages; and compromise of the integrity of our games and betting markets. Any such incident could subject us to significant remediation costs, litigation, regulatory investigations and penalties (including under applicable data privacy and gaming laws), loss of gaming licenses in one or more jurisdictions, increased insurance costs, loss of customer trust, and reputational harm, any of which could materially and adversely affect our business, financial condition, and results of operations. In addition, because techniques used to obtain unauthorized access change frequently and are often not recognized until launched against a target, we may be unable to implement adequate preventative measures in time.
Disruptions in the availability of our computer systems, through cyber-attacks or otherwise, could damage our computer or telecommunications systems, impact our ability to service our customers, adversely affect our operations and the results of operations, and have an adverse effect on our reputation. The costs to us to eliminate or alleviate security problems, bugs, viruses, worms, malicious software programs and security vulnerabilities could be significant, and the efforts to address these problems could result in interruptions, delays, cessation of service and loss of existing or potential customers and may impede our sales, distribution and other critical functions. We may also be subject to regulatory penalties and litigation by customers and other parties whose information has been compromised, all of which could have a material adverse effect on our business, results of operations and cash flows.
We face cyber security risks that could result in damage to our reputation and/or subject us to fines, payment of damages, lawsuits and restrictions on our use of data.
Our information systems and data, including those we maintain with our third-party service providers, may be subject to cyber security breaches. Computer programmers and hackers may be able to penetrate our network security and misappropriate, copy or pirate our confidential information or that of third parties, create system disruptions or cause interruptions or shutdowns of our internal systems and services. Our website may become subject to denial-of-service attacks, where a website is bombarded with information requests eventually causing the website to overload, resulting in a delay or disruption of service. Computer programmers and hackers also may be able to develop and deploy viruses, worms and other malicious software programs that attack our products or otherwise exploit any security vulnerabilities of our products. There is a growing trend of advanced persistent threats being launched by organized and coordinated groups against corporate networks to breach security for malicious purposes.
|
67 |
|
|
The techniques used to obtain unauthorized, improper, or illegal access to our systems, our data or customers' data, disable or degrade service, or sabotage systems are constantly evolving and have become increasingly complex and sophisticated, may be difficult to detect quickly, and often are not recognized or detected until after they have been launched. Although we have developed systems and processes designed to protect our data and customer data and to prevent data loss and other security breaches and expect to continue to expend significant resources to bolster these protections, there can be no assurance that these security measures will provide absolute security, as demonstrated by the incident described below.
There has been in the past, and may in the future be, losses or unauthorized access to or releases of confidential information, including personally identifiable information, that could subject the Company to significant reputational, financial, legal and operational consequences. It is increasingly difficult to differentiate legitimate from illegitimate claims and therefore take reasonable and appropriate action.
The Company's business requires it to use, transmit and store confidential information including, among other things, personally identifiable information ("PII") with respect to the Company's customers and employees. The Company devotes significant resources to network and data security, including through the use of encryption and other security measures intended to protect its systems and data. But these measures cannot provide absolute security, and losses or unauthorized access to or releases of confidential information have occurred, including the incident described above, and could occur again, and could materially adversely affect the Company's reputation, financial condition and operating results. The Company's business also requires it to share confidential information with third parties. Although the Company takes steps to secure confidential information that is provided to third parties, such measures are not always effective, and losses or unauthorized access to or releases of confidential information have occurred and could recur, which could materially adversely affect the Company's reputation, financial condition and operating results.
For example, on May 26, 2026, the Company received a communication from a threat actor claiming to have obtained sensitive customer information by accessing a former employees credentials. The threat actor demanded payment from the Company in exchange for not publicly disclosing this information. Following receipt of such communication, the Company could not confirm the details of the threat actors allegations. The collective claimed to have information including, in certain cases, unique citizen identification numbers, ID card and passport data, home addresses, and other identifying information.
Upon receipt of that threat actors claims, the Company immediately investigated various potential infiltration methods used by the threat actor and confirmed that it was likely that some information was exfiltrated. However, the Company has not been able to quantify the information taken. The Company then considered whether and how to patch its methods to contain, assess and remediate the alleged incident. The Company believes such prophylactic actions have been successful and, since the initiation of its responsive efforts, it has not observed any evidence of new unauthorized activity. Still, the Companys investigation, monitoring, and related activities are ongoing. The Company is actively engaged with local law enforcement and government partners in connection with the incident described herein. The Company is and will continue implementing further measures to strengthen its security environment and protect its customers. Although the Company has taken remedial measures, the Company cannot guarantee that all effects of the incident have been fully identified, remediated, or mitigated. If this threat actors claims were realized, the Company could face lawsuits, purported class actions, regulatory investigations and enforcement actions (and related fines, penalties, consent decrees, or other regulatory obligations), remediation costs, notification costs, reputational harm, loss of customers, contractual and business impacts, insurance premium increases (or loss of coverage), and increased cybersecurity compliance costs. Any of the foregoing consequences, individually or in the aggregate, could have a material adverse effect on the Companys business, financial condition, results of operations, and reputation, and consequently, the value of the Companys securities.
The effects of the above may result in a material adverse effect on our operations, cash flow, future prospects, and the value of our securities.
Nevertheless, to the Companys knowledge, the incident has not resulted in any material disruption to, or impact on, the Company's operations, its financial condition or results of operations.
Additionally, as with all companies, our security measures may not be sufficient for all eventualities and may be vulnerable to hacking, employee error, malfeasance, system error, faulty password management or other irregularities. In addition to the risks relating to general confidential information described above, the Company is also subject to specific obligations relating to payment card data. Under payment card rules and obligations, if cardholder information is potentially compromised, the Company could be liable for associated investigatory expenses and could also incur significant fees or fines if the Company fails to follow payment card industry data security standards. The Company could also experience a significant increase in payment card transaction costs or lose the ability to process payment cards if it fails to follow payment card industry data security standards, which would materially adversely affect the Companys reputation, financial condition and operating results.