XML 26 R17.htm IDEA: XBRL DOCUMENT v3.22.2.2
Cyber-Attack
9 Months Ended
Sep. 30, 2022
Extraordinary And Unusual Items [Abstract]  
Cyber-Attack

Note 9. Cyber-Attack

On February 20, 2022, management determined that the Company was the subject of a targeted cyber-attack. Upon discovering the incident, the Company shut down most of its connectivity, operating and accounting systems globally to manage the safety of its overall global systems environment, and initiated its cybersecurity incident response plan. The Company's security teams, supplemented by commercial cybersecurity experts and in collaboration with law enforcement, worked to remediate this cyber-attack. The Company undertook extensive efforts to identify, contain, eradicate and methodically recover from this attack as rapidly as possible. The Company had limited ability to conduct operations for a period of approximately three weeks including but not limited to arranging for shipments of freight or managing customs and distribution activities for its customers’ shipments and performing accounting functions. The Company’s teams worked to maintain its business operations and minimize the impact on its employees, customers and operating partners, including regulatory agencies. The Company continues to navigate the residual effects and incorporate learnings from the cyber-attack.

 

For the nine-month period ended September 30, 2022, the Company has incurred, as a result of its inability to timely process and move shipments through ports during the downtime, approximately $55 million in incremental demurrage charges where the Company has direct liability for this obligation. These costs are recorded in customs brokerage and other services expenses. During the three months ended September 30, 2022, the Company revised earlier estimates of these costs downward by $7 million. The Company is seeking recovery of the incremental demurrage charges it has incurred from service providers and ports. Any recoveries would be recorded in the period that they are realized.

Additionally, principally in the first quarter, the Company incurred investigation, recovery, and remediation expenses, including costs to recover its operational and accounting systems and to enhance cybersecurity protections. These costs are primarily comprised of various consulting services including cybersecurity experts, outside legal advisors, and other IT professional expenses. The Company also recorded estimated liabilities for potential shipment-related claims. For the nine-month period ended September 30, 2022, the total amount recorded for these items were approximately $15 million and is recorded in other operating expenses. During the three months ended September 30, 2022, the Company revised earlier estimates of these costs downward by $11 million. The Company does not expect to incur significant capital expenditures as a result of the cyber-attack.

The Company may incur additional expenses which could include third-party expenses, increased information services costs, or indemnities to customers. When the Company’s operating systems were down, many customers worked with other providers to meet their logistics needs, resulting in lower shipment volumes in the first quarter and to a lesser extent in the second quarter for which the financial impact on revenues and operating income cannot be quantified. Such costs and the ongoing impacts from the downtime caused by the cyber-attack are not expected to have further material adverse impact on the Company’s business. The Company is unable to estimate the ultimate direct and indirect financial impacts of this cyber-attack.