Business Context and Reporting Period
Company: PROG Holdings, Inc.
Filing Type: Form 8-K (Current Report)
Date of Report: September 18, 2023
Reporting Period: Event-based disclosure regarding a cybersecurity incident affecting the Progressive Leasing subsidiary.
Key Financial Metrics
This filing does not contain standard financial performance metrics such as revenue, profit, cash flow, margins, debt, or liquidity. The document focuses exclusively on a material event (cybersecurity incident) rather than periodic financial results.
Material Changes and Incident Details
- Incident: A cybersecurity incident was detected affecting certain systems of the Progressive Leasing subsidiary.
- Data Compromise: Preliminary findings indicate the involvement of a substantial amount of personally identifiable information (PII), including social security numbers, belonging to customers and other individuals.
- Operational Impact: No major operational impact to Progressive Leasing services; other subsidiaries were not impacted.
- Response Actions: The Company engaged third-party cybersecurity experts, notified law enforcement, and initiated remediation and investigation efforts.
- Notifications: Affected individuals and regulatory authorities will be notified in accordance with applicable laws.
Outlook, Risks, and Management Commentary
- Financial Impact: The Company has incurred and may continue to incur significant expenses for response, remediation, and investigation. The extent to which these costs will be offset by cybersecurity insurance has not been determined.
- Materiality Assessment: Management does not currently expect the incident to have a material effect on the Company's financial condition or results of operations, though the full scope of costs and impacts remains undetermined.
- Risks: Potential risks include fines, penalties, loss of reputation, customer attrition, litigation, and regulatory proceedings. The investigation is ongoing, and additional information may alter the assessment of the incident's impact.
Investor Verification Checklist
- Verify the final scope of data compromised and the number of individuals affected once the investigation concludes.
- Monitor future filings for updates on the total costs incurred and the extent of insurance coverage applied.
- Watch for announcements regarding regulatory fines, penalties, or class-action litigation arising from the incident.
- Review subsequent quarterly reports to confirm the absence of material financial impact as currently projected by management.