We collect and retain large volumes of data from employees and independent consultants, including credit card numbers and other personally identifiable information, for business purposes, including transactional and promotional purposes. Our various information technology systems enter, process, summarize and report such data. The integrity and protection of this data are critical to our business. We are subject to significant security and privacy regulations, as well as requirements imposed by the credit card industry.
Similarly, a failure to adhere to the payment card industry's data security standards could cause us to incur penalties from payment card associations, termination of our ability to accept credit or debit card payments, litigation and adverse publicity, any of which could have a material adverse effect on our business and financial condition.
Maintaining compliance with these evolving regulations and requirements could be difficult and may increase costs. In addition, a penetrated or compromised data system or the intentional, inadvertent or negligent release or disclosure of data could result in theft, loss or fraudulent or unlawful use of company, employee, consultant or guest data which could adversely affect our reputation, disrupt our operations, or result in remedial and other costs, fines or lawsuits, which could have a material adverse effect on our results of operations and financial condition. Although we take measures to protect the security, integrity and confidentiality of our data systems, we experience cyber-attacks of varying degrees and types on a regular basis. Our infrastructure may be vulnerable to these attacks, and in some cases, it could take time to discover them. Breaches of our data systems, or those of our vendors, whether from circumvention of security systems, denial-of-service attacks or other cyber-attacks, hacking, "phishing" attacks, computer viruses, ransomware or malware, employee or insider error, malfeasance, social engineering, vendor software supply chain compromises, physical breaches or other actions, could result in material interruptions or malfunctions in our or such vendors' websites, applications, data processing, or disruption of other business operations. For example, in February 2023 we were targeted by a sophisticated social engineering attack, in which a third party fraudulently induced personnel at our wholly owned subsidiary in Japan to make wire transfers totaling $4.8 million. These and other attacks could result in additional losses and harm our business and results of operations.
For various reasons or circumstances, our employees may work remotely from time to time. During such times, remote access heightens the risk of a cyber-attack. Additionally, outside parties may attempt to fraudulently induce employees, users, or customers to disclose sensitive information to gain access to our data or our users' or customers' data. Any such breach or unauthorized access could result in the unauthorized disclosure, misuse or loss of sensitive information and lead to significant legal and financial exposure, regulatory inquiries or investigations, loss of confidence by our sales force, disruption of our operations and damage to our reputation. These risks are heightened as we work with third-party partners and as our sales force uses social media, as the partners and social media platforms could be vulnerable to the same types of breaches.