Fiscal period ending 2025-12-31 versus 2024-12-31
— view filing on EDGAR →
A confirmed January 2026 social engineering breach, Apple's removal of the Azar app from the App Store, and newly disclosed debt-service and restructuring risks collectively mark a substantive deterioration across multiple risk dimensions. Cybersecurity alone accounts for six distinct new or escalated disclosures — including biometric/location data exposure, AI governance gaps, and employee misuse — while the Azar removal cascades into competitive, operational, M&A integration, and potential goodwill impairment risks. Two partial offsets — payoff of the $425M term loan and removal of prior M&A integration disclosures — are insufficient to change the overall direction.
15 company-specific
· 2 eased/removed
· 4 common-mode
Company-specific changes
Revised
New material disclosure: Apple removed Azar app from App Store (Feb 2026), creating concrete user base and revenue risk. Adds specific, quantifiable threat beyond generic user retention language.
Risks relating to our business If we fail to retain existing users or add new users, or if our users do not convert to paying users, our revenue, financial results, and business may be significantly…
New
New disclosure of active, ongoing restructuring with headcount reductions, operational disruption risks, and execution uncertainty on reinvestment strategy.
Our restructuring and reorganization activities may be disruptive to our operations and harm our business, and the investments we make in our business with the savings from such activities may not…
Revised
Concrete example added: Apple removed Azar app from App Store in Feb 2026. Specific fee escalation risk disclosed (Google partnership expires Q1 2027 with expected fee increase). Material operational impact.
Distribution and marketing of, and access to, our services rely, in significant part, on a variety of third-party platforms, in particular, mobile app stores. In the past, some of these third parties…
Revised
Added specific active litigation in Colorado and Texas; expanded harm examples (scams, fraud, trafficking, terrorism recruitment); acknowledged monitoring failures. Materially escalated risk disclosure.
Inappropriate actions by certain of our users could be attributed to us or may not be adequately prevented by us and consequently damage our brands’ reputations, which in turn could adversely…
Revised
New specific impairment risk disclosed: Apple's removal of Azar app from App Store may trigger future goodwill/intangible asset impairment charges, escalating from generic boilerplate to concrete event-driven risk.
We have incurred impairment charges related to our intangible assets in the past and may incur further impairment charges related to our goodwill and other intangible assets in the future, which…
Revised
Added disclosure of specific January 2026 breach with social engineering attack and unauthorized access to internal tools and user data. Expanded scope to include biometric and location data. Concrete incident escalates risk materiality.
If the security of personal and confidential or sensitive user information that we maintain and store is breached or otherwise accessed by unauthorized persons, it may be costly to mitigate the…
New
Newly disclosed material risk: open source software could force proprietary code release, litigation, costly re-engineering, or AI model discontinuation. Substantive operational and legal exposure.
Our use of “open source” software could subject our proprietary software to general release, adversely affect our ability to sell our services and subject us to possible litigation, and third…
New
New disclosure of acquisition integration risks and concrete example: Apple removed Azar app (acquired 2021) from App Store in Feb 2026, demonstrating realized loss of acquired asset value.
We have experienced, and in the future may again experience, operational and financial risks in connection with acquisitions. We have made acquisitions in the past and continue to seek potential…
Revised
Added specific examples of government blocking/throttling (Saudi Arabia, Turkey), expanded compliance risks (data sovereignty, AI, age assurance, content moderation), and acknowledged past adverse impacts.
We operate in various international markets, including certain markets in which we have limited experience, and some of our brands continue to seek to increase their international scope. As a result…
New
New disclosure of material measurement risks in core user metrics (MAU, Payers, RPP) that drive valuation and strategic decisions. Acknowledges unvalidated methodologies, potential inaccuracies, and reputational/operational impact if metrics prove unreliable.
Our user metrics and other estimates are subject to inherent challenges in measurement, and real or perceived inaccuracies in those metrics may adversely affect our business, results of operations…
Revised
Added material new risks: reliance on facial/liveness verification, past outage history, AI governance gaps, and AI provider instability concerns.
Our success depends, in part, on the integrity of third-party systems and infrastructure. We rely on third parties, primarily data center and cloud-based, hosted web service providers, such as Amazon…
Revised
New specific incident disclosed (January 2026 social engineering attack with unauthorized access). Agentic AI threat newly highlighted. Concrete example elevates risk perception.
We may not be able to protect our systems and infrastructure from cyberattacks and may be adversely affected by cyberattacks experienced by third parties. We are regularly under attack by…
Revised
New disclosure of employee/contractor AI misuse risk and IP ownership complications. Escalates internal control and data security exposure beyond prior external AI risks.
Challenges with properly managing the use of AI could result in reputational harm, competitive harm, and legal liability. We currently incorporate AI technologies into certain of our services and are…
Revised
Company expanded credit card transaction volume through new alternative payment methods outside Apple/Google platforms, increasing exposure to data breach and fraud risks.
We are subject to a number of risks related to credit card payments, including data security breaches and fraud that we or third parties experience, any of which could adversely affect our business…
Revised
New disclosure that newer advertising channels are "relatively undeveloped and unproven," escalating uncertainty about marketing effectiveness and ROI.
Our growth and profitability rely, in part, on our ability to attract and retain users through cost-effective marketing efforts. Any failure in those efforts could adversely affect our business…
Eased / removed
Removed
Material easing: $425M term loan paid off in full, eliminating variable-rate debt exposure and interest rate risk previously disclosed.
Variable rate indebtedness that we have incurred or may incur under our credit agreement will subject us to interest rate risk, which could cause our debt service obligations to increase…
Removed
Removal of acquisition risk disclosure, including specific Hakuna shutdown example, signals reduced M&A activity or resolved integration concerns. Material easing of previously disclosed strategic risk.
We have experienced, and in the future may again experience, operational and financial risks in connection with acquisitions. We have made acquisitions in the past and continue to seek potential…
Also disclosed — common-mode (AI cybersecurity escalation, Debt leverage refinancing, Generative AI competition disruption, AI regulatory compliance)
AI cybersecurity escalation
New
New comprehensive disclosure of material cybersecurity, data privacy, AI governance, and third-party infrastructure risks. Substantive addition addressing critical operational and reputational exposures.
Risks relating to systems and infrastructures, data, security, privacy, and the use of AI • Our success depends, in part, on the integrity of our systems and infrastructures and on our ability to…
Debt leverage refinancing
New
New disclosure of material debt risks: cash flow adequacy for debt service, secured indebtedness, and dilution from exchangeable notes. Substantive addition.
Risks relating to our indebtedness • Our indebtedness may affect our ability to operate our business, and we and our subsidiaries may incur additional indebtedness, including secured indebtedness.…
Generative AI competition disruption
Revised
Prior year focused on user retention and monetization challenges. This year explicitly adds competitive risk as a standalone factor, highlighting low switching costs and disruptive innovation threats.
Risk relating to our business • If we fail to retain existing users or add new users, or if our users do not convert to paying users, our revenue, financial results, and business may be…
AI regulatory compliance
Revised
Added explicit AI regulatory risk and expanded scope of regulatory matters. New specific risks: app removal from platforms, geographic bans, patchwork net neutrality requirements.
Risks relating to legal and regulatory compliance Our business is subject to complex and evolving U.S., foreign, and international laws and regulations, including with respect to data privacy…