v3.25.4
Cyber Related Matters
12 Months Ended
Nov. 30, 2025
Health Care Organizations [Abstract]  
Cyber Related Matters Cyber Related Matters
November 2022 Cyber Incident

Following the detection of irregular activity on certain portions of our corporate network, we engaged outside cybersecurity experts and other incident response professionals to conduct a forensic investigation and assess the extent and scope of the incident. Costs for this incident were primarily related to the engagement of external cybersecurity experts and other incident response professionals. We did not incur costs related to this incident during fiscal year 2024 or 2025 and do not expect to incur additional costs as the investigation is closed. For the fiscal year ended November 30, 2023, we incurred expenses of $4.7 million, net of insurance reimbursements, related to this incident.
MOVEit Vulnerability

As previously disclosed, on the evening of May 28, 2023, we learned that our MOVEit Transfer (the on-premise version) and MOVEit Cloud (a cloud-hosted version of MOVEit Transfer) products were attacked by a threat actor who compromised and exfiltrated personal data from various customer-controlled MOVEit Transfer environments (the "MOVEit Vulnerability"). As a result of the MOVEit Vulnerability, we are party to certain class action lawsuits filed by individuals who claim to have been impacted by the exfiltration of data from the environments of our MOVEit Transfer customers, which have been centralized in multi-district litigation in the District of Massachusetts (the "MDL"). The MDL has also consolidated the insurance subrogation complaint (where an insurer is seeking recovery for expenses incurred on behalf of its insured in connection with the MOVEit Vulnerability) and, as of the date of this filing, one customer cross-claim. The MDL remains in a relatively early stage and is not expected to conclude within the next twelve months. Motions to dismiss were filed and partially granted in July 2025, then further partially granted in January 2026 in response to our motions for reconsideration. In all, the court has dismissed 20 of the 33 claims asserted by the plaintiffs in the MDL.

As previously disclosed, we have also cooperated with inquiries and investigations from various domestic and foreign governmental authorities (data privacy regulators, a U.S. federal law enforcement agency, the Federal Trade Commission, and the SEC), a number of which have been formally closed and, as of the date of this filing, have not resulted in any prosecution or enforcement actions against us. We continue to support inquiries and investigations from several state attorneys general, one of which has been formally closed without any enforcement or regulatory actions directed against us.

Our financial liability arising from the MOVEit Vulnerability will depend on many factors, including the progression of the MDL and additional litigation or indemnification claims, and any settlements resulting from remaining or additional governmental or regulatory investigations; therefore, we are unable at this time to estimate the quantitative impact of any such liability with any reasonable degree of certainty. As our litigation response continues, we will continue to assess the potential impact of the MOVEit Vulnerability on our business, operations, and financial results. Such claims and investigations may have an adverse effect on how we operate our business and our results of operations, and in the future, we may be subject to additional governmental or regulatory investigations, as well as additional litigation or indemnification claims. MOVEit Transfer and MOVEit Cloud represented less than 3% in aggregate of our revenue for the fiscal year ended November 30, 2025.

Expenses Incurred and Future Costs

For the fiscal years ended November 30, 2025, 2024, and 2023, we incurred net costs of $2.8 million, $5.6 million, and $1.5 million, respectively, related to the MOVEit Vulnerability. The costs recognized are net of insurance recoveries of $2.2 million, $2.1 million, and $3.7 million, respectively. The timing of recognizing insurance recoveries may differ from the timing of recognizing the associated expenses.

We expect to continue to incur investigation, legal and professional services expenses associated with the MOVEit Vulnerability in future periods. We will recognize these expenses as services are received, net of insurance recoveries. While a loss from these matters is reasonably possible, we cannot reasonably estimate a range of possible losses at this time, particularly while the foregoing matters remain ongoing. Furthermore, with respect to the MDL, the proceedings remain in the relatively early stages, alleged damages have not been specified, there is uncertainty as to the likelihood of a class or classes being certified or the ultimate size of any class if certified, and there are significant factual and legal issues to be resolved. With respect to governmental inquiries and investigations, we are currently unable to reasonably estimate any possible adverse judgments, settlements, fines, or penalties. Therefore, we have not recorded a loss contingency liability for the MOVEit Vulnerability as of November 30, 2025.

Insurance Coverage

During the period when the November 2022 Cyber Incident and the MOVEit Vulnerability occurred, we maintained $15.0 million of cybersecurity insurance coverage, which is expected to reduce our exposure to expenses and liabilities arising from these events. As of November 30, 2025, we have approximately $4.5 million of remaining cybersecurity insurance coverage under the applicable policy. We will pursue recoveries to the maximum extent available under our insurance policies.