|
Subsequent Events
|3 Months Ended
Mar. 31, 2023
|Subsequent Events [Abstract]
|Subsequent Events
|
14. Subsequent Events
Commitments and Contingencies
In early April 2023, the Company detected a cybersecurity incident as part of its routine security monitoring protocols. In response to the incident, the Company launched an investigation with the support of leading cybersecurity experts, reached out to law enforcement and has taken and will continue to take actions to implement additional safeguards.
The Company’s solutions are operational, and customer transactions continue to be processed through the Company's systems. However, the Company’s efforts to respond to the incident and to implement additional safeguards and enhance the Company’s security have resulted and may continue to result in temporary disruptions to certain features or products.
The investigation, which is ongoing as of the date of filing of this quarterly report on Form 10-Q, has so far revealed that the incident affected certain of AvidXchange’s systems and that some data from these systems was exfiltrated. The Company is aware that one or more threat actors have published files they claim to have taken from the Company’s systems. Upon reviewing the files published online, the Company learned that the threat actor(s) published, among other materials, some credentials for internal Company applications and credentials for a specific application used by a small number of customers. The Company temporarily took the application used by customers offline, contacted impacted customers, reset impacted credentials and took other related security measures. The Company posted notice of the event on its website and is continuously reviewing and evaluating the situation and the Company’s notification and disclosure obligations as additional information becomes available.
Beginning in the second fiscal quarter of 2023, the Company has incurred significant costs associated with the cybersecurity incident. The Company expects that it will continue to experience increased costs related to its threat response and its actions to implement additional safeguards. The Company maintains cyber insurance and will likely seek reimbursement for certain of the expenses incurred in connection with this event, although the extent to which its insurance will cover such expenses remains uncertain. The Company is unable at this time to reasonably estimate the possible loss or range of loss and no liability has been recorded related to the incident as of March 31, 2023.
Share Issuance
On May 1, 2023, the Company issued 194,508 shares of common stock under its employee stock purchase plan at a purchase price of $6.10 per share representing a 15% discount on the closing price of $7.18 on the date of purchase for an aggregate of $1,186. The purchase price is based on the lower of the fair market value of the Company’s common stock at the grant date or purchase date.
|X
- References
+ Details
No definition available.
|X
- Definition
+ References
The entire disclosure for significant events or transactions that occurred after the balance sheet date through the date the financial statements were issued or the date the financial statements were available to be issued. Examples include: the sale of a capital stock issue, purchase of a business, settlement of litigation, catastrophic loss, significant foreign exchange rate changes, loans to insiders or affiliates, and transactions not in the ordinary course of business.
+ Details
Reference 1: http://www.xbrl.org/2003/role/disclosureRef