XML 36 R22.htm IDEA: XBRL DOCUMENT v3.8.0.1
Subsequent Events
3 Months Ended
Mar. 31, 2018
Subsequent Events [Abstract]  
Subsequent Events
Subsequent Events

On April 26, 2018, Company personnel identified suspicious activity primarily on systems involving the Company’s Stored Value Solutions gift card business. The Company took immediate action to stop the activity and limit the improper use of accessed private label gift card information (these gift cards do not contain personally identifiable information such as consumer names, Social Security numbers, driver’s license numbers and other sensitive personal data). The Company through counsel has retained three information technology forensic firms, which have been examining the Company’s systems in detail over the approximately two week period since the incident was discovered. The Company also contacted federal law enforcement and merchants known to be affected. As of the date hereof, the Company does not believe that the unauthorized access incident will have a material adverse effect on its business and results of operations, though the Company’s investigation is ongoing.
Based upon information known as of the date hereof, the Company believes that a significant number of gift card and PIN numbers issued by six Stored Value Solutions customers were accessed. Following discovery, the Company has been working with merchant customers to limit the impact of the unauthorized access. We believe the mitigation steps discussed with merchants, if fully implemented, will severely restrict or eliminate the ability of the bad actors to use the information, while preserving the ability of legitimate holders of the gift cards to use them.
The Company has no evidence of access affecting its systems involving fleet cards and other payment products, or the proprietary and third-party payment networks used to deliver the Company’s payment solutions.
Subsequent to March 31, 2018, the Company has incurred, and expects to continue to incur, legal and other professional expenses related to the unauthorized access incident in future periods. The Company will recognize these expenses as services are received.
The Company maintains insurance coverage to limit its exposure to losses such as those related to the unauthorized access incident. The Company has not recorded a receivable for costs the Company has incurred to date as we have not yet concluded that the costs are reimbursable and probable of recovery under our insurance coverage.