Cyberattacks, denial-of-service attacks, ransomware attacks, business email compromises, computer malware, viruses, social engineering (including phishing) and other malicious internet-based activity are prevalent in our industry and such attacks continue to increase. We also utilize third-party providers to host, transmit, or otherwise process electronic data in connection with our business activities. We or our vendors and business partners may experience attacks, unavailable systems, unauthorized access, or disclosure due to employee or other theft or misuse, denial-of-service attacks, sophisticated attacks by nation-state and nation-state supported actors, and advanced persistent threat intrusions. Despite our efforts to ensure the security, privacy, integrity, confidentiality, availability, and authenticity of information technology networks and systems, processing and information, we may not be able to anticipate, or to implement, preventive and remedial measures effective against all data security and privacy threats. The recovery systems, security protocols, network protection mechanisms, and other security measures that we have integrated into our systems, networks, and physical facilities, may not be adequate to prevent or detect service interruption, system failure, data loss or theft, or other material adverse consequences. No security solution, strategy, or measures can address all possible security threats or block all methods of penetrating a network or otherwise perpetrating a security incident. The risk of unauthorized circumvention of our security measures, or those of our third-party providers, clients, and partners has been heightened by advances in computer and software capabilities and the increasing sophistication of hackers who employ complex techniques, including without limitation, the theft or misuse of personal and financial information, counterfeiting, "phishing" or social engineering incidents, ransomware, extortion, publicly announcing security breaches, account takeover attacks, denial or degradation of service attacks, malware, fraudulent payment, and identity theft.
In 2021, we experienced an unauthorized access into our online insurance quote feature whereby attackers used personal information already in their possession to obtain additional consumer data, including driver's license numbers. While none of our systems or databases were compromised or significantly disrupted as part of this incident and the costs associated with the incident and our remediation efforts were not material, we could be subject to litigation or regulatory enforcement actions. In 2023, the Company accrued an estimated liability related to this incident based on the facts known by management and developed through its assessment of the current status of ongoing dialog with the regulatory investigators. The amount of the estimated liability is not material to our Consolidated Financial Statements, though any actual fines, penalties, or settlements may differ from our estimates and the amounts accrued.
Any regulatory enforcement actions, or future cyberattacks on our systems, could cause irreparable harm to our reputation and lead our current and prospective Members away from using our services. Further, we may be required to expend significant financial and operational resources in response to a security breach, including repairing system damage, increasing security protection costs by deploying additional personnel and protection technologies, and defending against and resolving legal and regulatory claims, all of which could be costly and divert resources and the attention of our management and key personnel away from our business operations.