|
Commitments and Contingencies
|6 Months Ended
Jun. 30, 2023
|Commitments and Contingencies Disclosure [Abstract]
|Commitments and Contingencies
|
12. Commitments and Contingencies
Letters of Credit
As of June 30, 2023, the Company has an irrevocable standby letter of credit outstanding that acts as collateral with respect to the lease of the Company’s Charlotte corporate headquarters with an availability of approximately $6,072 for which the Company pays a fee of 2.5% to 3.0% per annum, primarily based on the ratio of debt under the 2022 Credit Agreement to the Company’s consolidated software revenue. The letter of credit reduces the borrowing capacity under the 2022 Revolver. It renews annually and expires on December 1, 2023. The letter of credit was canceled on July 1, 2023 as described in Note 14.
Cybersecurity Incident
In early April 2023, the Company detected a cybersecurity incident as part of its routine security monitoring protocols. In response to the incident, the Company launched an investigation with the support of leading cybersecurity experts, reached out to law enforcement and has taken and will continue to take actions to implement additional safeguards.
The Company’s solutions are operational, and customer transactions continue to be processed through the Company's systems. No threat actor activity has been detected on the Company’s network and systems since April 27, 2023.
The investigation, which is ongoing as of the date of filing of this Quarterly Report on Form 10-Q, has determined that data was exfiltrated from certain AvidXchange systems and posted on the dark web. The Company is reviewing the published data. As of the date of filing of this Quarterly Report on Form 10-Q, the Company has identified personally identifiable information, primarily information of Company employees and their dependents, and the bank account information of some customers in the files published online. The Company continues to review the files published online to identify additional bank account information and any other confidential information and any personally identifiable information that requires notification under state law. The Company believes that this review will extend through the third fiscal quarter of 2023. The Company has posted notice of the event on its website and is continuously reviewing and evaluating the situation and the Company’s notification and disclosure obligations as additional information becomes available. The Company has cooperated with inquiries about the incident from two state financial service regulators.
Expenses Incurred and Future Costs
During the second fiscal quarter of 2023, the Company incurred costs of $3,616 in response to the incident, including professional services and legal fees. The Company expects that it will continue to experience significant expenses and increased costs associated with this cybersecurity incident. While a loss from these matters is possible, the Company is unable at this time to reasonably estimate the possible loss or range of loss, and the Company’s investigation into the matter is ongoing. Therefore, no liability has been recorded related to the incident as of June 30, 2023.
Insurance Coverage
The Company maintains cyber insurance coverage and will be tendering claims for certain expenses incurred in connection with this event. The extent to which its insurance will cover such expenses remains uncertain.
|X
- References
+ Details
No definition available.
|X
- Definition
+ References
The entire disclosure for commitments and contingencies.
+ Details
Reference 1: http://www.xbrl.org/2003/role/disclosureRef