XML 270 R9.htm IDEA: XBRL DOCUMENT v3.23.1
Basis of Presentation
3 Months Ended
Apr. 01, 2023
Basis of Presentation [Abstract]  
Basis of Presentation Basis of Presentation
These statements have been prepared pursuant to the rules and regulations of the Securities and Exchange Commission (the “SEC”) and, in accordance with those rules and regulations, do not include all information and footnote disclosures normally included in annual financial statements prepared in accordance with accounting principles generally accepted in the United States of America (“GAAP”). Management believes that the disclosures made are adequate for a fair statement of the results of operations, financial condition and cash flows of Hanesbrands Inc. and its consolidated subsidiaries (the “Company” or “Hanesbrands”). In the opinion of management, the condensed consolidated interim financial statements reflect all adjustments, which consist only of normal recurring adjustments, necessary to state fairly the results of operations, financial condition and cash flows for the interim periods presented herein. The preparation of condensed consolidated interim financial statements in conformity with GAAP requires management to make use of estimates and assumptions that affect the reported amounts and disclosures. Actual results may vary from these estimates.
These condensed consolidated interim financial statements should be read in conjunction with the consolidated financial statements and notes thereto included in the Company’s Annual Report on Form 10-K for the year ended December 31, 2022. The year-end condensed consolidated balance sheet data was derived from audited consolidated financial statements, but does not include all disclosures required by GAAP. The results of operations for any interim period are not necessarily indicative of the results of operations to be expected for the full year or any future period.
Ransomware Attack
As previously disclosed, on May 24, 2022, the Company identified that it had become subject to a ransomware attack and activated its incident response and business continuity plans designed to contain the incident. As part of the Company’s forensic investigation and assessment of the impact, the Company determined that certain of its information technology systems were affected by the ransomware attack.
Upon discovering the incident, the Company took a series of measures to further safeguard the integrity of its information technology systems, including working with cybersecurity experts to contain the incident and implementing business continuity plans to restore and support continued operations. These measures also included resecuring data, remediation of the malware across infected machines, rebuilding critical systems, global password reset and enhanced security monitoring. The Company notified appropriate law enforcement authorities as well as certain data protection regulators. In addition to the Company’s public announcements of the incident, the Company provided breach notifications and regulatory filings as required by applicable law starting in August 2022, and that notification process is complete. The Company believes the incident has been contained, the Company has restored its critical information technology systems, and manufacturing, retail and other internal operations continue. There is no ongoing operational impact on the Company’s ability to provide its products and services. The Company maintains insurance, including coverage for cyber-attacks, subject to certain deductibles and policy limitations, in an amount that the Company believes appropriate.
The Company is named in two pending lawsuits in connection with its previously disclosed ransomware incident. On October 7, 2022, a putative class action, entitled Roman v. Hanes Brands [sic], Inc., was filed in the United States District Court for the Central District of California. The lawsuit alleges, among other things, negligence, negligence per se, breach of implied contract, unjust enrichment, breach of implied covenant of good faith and fair dealing, unfair business practices under the California Business and Professions Code, and violations of the California Confidentiality of Medical Information Act in connection with the ransomware incident. On October 13, 2022, another putative class action, entitled Toussaint v. HanesBrands,[sic] Inc., was filed in the United States District Court for the Middle District of North Carolina. The lawsuit alleges, among other things, negligence, negligence per se, breach of implied contract, invasion of privacy, and unjust enrichment in connection with the ransomware incident. The pending lawsuits seek, among other things, monetary and injunctive relief. The lawsuits have been consolidated in the United States District Court for the Middle District of North Carolina, and Plaintiffs have been granted leave to file a consolidated complaint. Plaintiff Roman also filed a second putative class action with regard to the ransomware incident in the United States District Court for the Middle District of North Carolina on January 16, 2023, entitled Roman v. Hanesbrands,[sic] Inc., which was voluntarily dismissed without prejudice on January 20, 2023. The Company is vigorously defending the remaining pending matters and believes the cases are without merit. The Company does not expect any of these claims, individually or in the aggregate, to have a material adverse effect on its
consolidated financial position or results of operations. However, at this early stage in the proceedings, the Company is not able to determine the probability of the outcome of these matters or a range of reasonably expected losses, if any.
During the quarter ended April 1, 2023, the Company incurred no net costs related to the ransomware attack. Minimal legal fees and the offsetting expected insurance recoveries are reflected in the “Selling, general and administrative expenses” line of the Condensed Consolidated Statements of Income. The Company cannot determine, at this time, the full extent of any proceedings or additional costs or expenses related to the security event or whether such impact will ultimately have a material adverse effect.