We are a trusted provider to government and other clients of critical health and human services that rely heavily upon technology systems, software, and networks to receive, input, maintain, and communicate participant and client data. The risk of a security breach, system disruption, ransom-ware attack, or similar cyber-attack or intrusion, including by computer hackers, cyber terrorists, or foreign governments, is persistent and substantial as the volume, intensity, and sophistication of attempted attacks, intrusions and threats from around the world increase daily. If our systems or networks are compromised, we could be adversely affected by losing confidential or protected information of program participants and clients or by facing a demand for ransom to prevent disclosure of or to restore access to such information. The loss, theft, or improper disclosure of that information could subject us to sanctions under the relevant laws, breach of contract claims, contract termination, class action, or individual lawsuits from affected parties, negative press articles, reputational damage, and a loss of confidence from our government clients, all of which could adversely affect our existing business, future opportunities, and financial condition. Additionally, if our internal networks were compromised, we could suffer the loss of proprietary, trade secret, or confidential technical and financial data. That could make us less competitive in the marketplace and adversely affect our existing business, future opportunities, and financial condition.
We have experienced cybersecurity incidents in the past that were immaterial, and in the third quarter of fiscal year 2023, we experienced a material cybersecurity incident as the personal information of a significant number of individuals was accessed by an unauthorized third party by exploiting a zero-day vulnerability in a third-party vendor's file transfer application used by many organizations, including us. We have recorded expenses in connection with our investigation and remediation activities related to this incident; further details are included in "Note 15. Commitments and Contingencies" in Item 8 of this Annual Report on Form 10-K. We may continue to experience cybersecurity incidents in the future. There can be no guarantee that our preventative and remediation efforts will be sufficient to protect the company's information systems, information, and other assets from significant harm and that future cybersecurity incidents will not have a material adverse effect on the company or its results of operations or financial condition or cause reputational or other harm to the company. For more information regarding our cybersecurity risk management, see "Item 1C. Cybersecurity" of this Annual Report on Form 10-K.