A ransomware incident identified early in 2025 affected the Company's operating systems, which were recovered without paying a ransom. A first-quarter 2026 investigation by a third-party consulting firm determined that the incident resulted in exfiltration of some employee information, including names, addresses, and Social Security numbers. Affected-individual notifications are ongoing. The Company reports no material operational impact and additional safeguards have been implemented.