We and third parties collect, process, transfer, host, store, analyze, retain, provide access to and dispose of account information, payment transaction information, and certain types of personally identifiable and other information pertaining to our customers and colleagues in connection with our cards and other products and in the normal course of our business.
Global financial institutions like us, as well as our customers, colleagues, regulators, service providers and other third parties, have experienced a significant increase in information security and cybersecurity risk in recent years and will likely continue to be the target of increasingly sophisticated cyberattacks, including computer viruses, malicious or destructive code, ransomware, social engineering attacks (including phishing, impersonation and identity takeover attempts), artificial intelligence-assisted deepfake attacks and disinformation campaigns, corporate espionage, hacking, website defacement, denial-of-service attacks, exploitation of vulnerabilities and other attacks and similar disruptions from the misconfiguration or unauthorized use of or access to computer systems. These threats can arise from external parties, as well as insiders who knowingly or unknowingly engage in or enable malicious cyber activities. There are a number of motivations for cyber threat actors, including criminal activities such as fraud, identity theft and ransom, corporate or nation-state espionage, political agendas, public embarrassment with the intent to cause financial or reputational harm, intent to disrupt information technology systems and supply chains, and to expose and exploit potential security and privacy vulnerabilities in corporate systems and websites. Cyber threat actors have increasingly demonstrated advanced capabilities, including the rapid integration of new technology such as advanced forms of artificial intelligence and quantum computing. Cyber threats, including attacks from state sponsored or nation-state actors, can increase during periods of diplomatic or armed conflict, such as the ongoing Russia-Ukraine and Israel-Hamas wars.
Our networks and systems are subject to constant attempts to disrupt our business operations and capture, destroy, manipulate or expose various types of information relating to corporate trade secrets, customer information, including Card Member, travel and loyalty program data, colleague information and other sensitive business information, including acquisition activity, non-public financial results and intellectual property. For example, we and other U.S. financial services providers have been the target of distributed denial-of-service attacks. We develop and maintain systems and processes aimed at detecting and preventing information security and cybersecurity incidents and fraudulent activity, which require significant investment, maintenance and ongoing monitoring and updating as technologies and regulatory requirements change, new vulnerabilities and exploits are discovered and as efforts to overcome security measures become more sophisticated. In addition, we maintain cyber crisis response procedures and regularly test our procedures to remain prepared and reduce the risk of harm to our business operations, customers and third parties in the event of an information or cybersecurity incident.
Despite our efforts and the efforts of third parties that process, transmit or store our data and data of our customers and colleagues or support our operations, such as service providers, merchants and regulators, the possibility of information, operational and cybersecurity incidents, malicious social engineering, password mismanagement, corporate espionage, fraudulent or other malicious activities and human error or malfeasance cannot be eliminated entirely and will evolve as new and emerging technology is deployed, including quantum computing and the increasing use of platforms that are outside of our network and control environments. For example, we are aware that certain of our third-party service providers have been the victims of ransomware and other cyberattacks, in some instances that affected our data or the services they provide to us. In addition, new products and services, such as checking accounts and non-card lending, may lead to an increase in the number or types of cyber attacks and our exposure to fraud and other malfeasance. Risks associated with such incidents and activities include theft of funds and other monetary loss, disruption of our operations and the unauthorized disclosure, release, gathering, monitoring, misuse, modification, loss or destruction of confidential, proprietary, trade secret or other information (including account data information). An incident may not be detected until well after it occurs and the severity and potential impact may not be fully known for a substantial period of time after it has been discovered. Our ability to address incidents may also depend on the timing and nature of assistance that may be provided from relevant governmental or law enforcement agencies.
Information, operational or cybersecurity incidents, fraudulent activity and other actual or perceived failures to maintain confidentiality, integrity, availability of services, privacy and/or security has led to increased regulatory scrutiny and may lead to regulatory investigations and intervention (such as mandatory card reissuance), consent decrees, increased litigation (including class action litigation), response costs (including notification and remediation costs), fines, negative assessments of us and our subsidiaries by banking regulators and rating agencies, reputational and financial damage to our brand, negative impacts to our partner relationships, and reduced usage of our products and services, all of which could have a material adverse impact on our business. The disclosure of sensitive company information could also undermine our competitive advantage and divert management attention and resources.
Successful cyberattacks, data breaches, disruptions or other incidents related to the actual or perceived failures to maintain confidentiality, integrity, data availability, privacy and/or security at other large financial institutions, large retailers, travel and hospitality companies, government agencies or other market participants, whether or not we are impacted, could lead to a general loss of customer confidence that could negatively affect us, including harming the market perception of the effectiveness of our security measures or harming the reputation of the financial system in general, which could result in reduced use of our products and services. Such events could also result in legislation and additional regulatory requirements. Although we maintain cyber insurance, there can be no assurance that liabilities or losses we may incur will be covered under such policies or that the amount of insurance will be adequate.