Our business is heavily dependent upon information technology networks and systems, including those of our vendors, suppliers and partners. Internal or external attacks on those networks and systems could disrupt our normal operations centers and impede our ability to provide critical products and services to our customers, subjecting us to liability under our contracts and damaging our reputation. Additionally, such attacks could compromise our, or our customers' or vendors', intellectual property or confidential information or result in fraud or other financial loss. For example, in July 2021, we announced publicly that a threat actor had gained access to our systems. That incident did not have a material impact to the business. In July 2022 and September 2023, we became aware that a sophisticated threat actor gained access to a portion of our networks and systems. After conducting a thorough review of those attacks with a leading third-party cybersecurity firm, we determined that those attacks did not have a material impact on us. Evidence indicates that the threat actor responsible for these incidents is related to, or the same as, the threat actor that previously gained unauthorized access to our systems in July 2021.
In response to these threats, we engaged in remedial and preventative actions to remove the threat actor and prevent further unauthorized access to our network, analyzed the information that the threat actors accessed, enhanced our data security and governance program, added additional protective security layers and are cooperating with law enforcement authorities. While we do not believe at this time that these cyber-attacks had a material impact on our systems or operations, should new or different information come to light establishing that the intrusions are broader than now known or if additional attacks occur, it could have a broader impact on our systems and operations, and we could incur significant costs in responding to such intrusions.
Our business also involves the use, storage and transmission of information about our co-workers, and customers. If any person, including any of our co-workers, negligently disregards or intentionally breaches our established controls with respect to such data or otherwise mismanages or misappropriates that data, we could be subject to monetary damages, fines or criminal prosecution.
We have security controls for our systems and other security practices in place to protect the security of, and prevent unauthorized access to, our systems and personal and proprietary information, such as firewalls and anti-virus software, and we also provide information to our co-workers about the need to deploy security measures and the impact of doing so; however, notwithstanding our efforts to date, there are numerous sophisticated threat actors that are actively engaging in cyber-attacks that include our systems and there can be no assurance that such security measures will prevent additional improper access to our networks and systems, or access to or disclosure of, personally identifiable or proprietary information which could harm our business.
We could also face legal, reputational and financial risks if we fail to protect customer and internal data from security breaches or cyberattacks.
Furthermore, data privacy is subject to frequently changing rules and regulations, which sometimes conflict among the various jurisdictions and countries in which we provide services. The General Data Protection Regulation ("GDPR") in Europe, the California Consumer Privacy Act and other similar laws have resulted, and will continue to result, in increased compliance costs. Our failure to adhere to or successfully implement processes in response to these and other changing regulatory requirements in this area could result in legal liability or impairment to our reputation in the marketplace, which could have a material adverse effect on our business, financial condition and results of operations.