Changes in federal, state and local, or foreign tax laws, changing interpretations of existing tax laws, or adverse determinations by tax authorities could increase our tax burden or otherwise adversely affect our results of operations, and financial condition.
We are subject to taxation at the federal, state, provincial, and local levels in the U.S., the U.K., and various other countries and jurisdictions in which we operate, including income taxes, sales taxes, value-added (“VAT”) taxes, and similar taxes and assessments. The laws and regulations related to tax matters are extremely complex and subject to varying interpretations. Although we believe our tax positions are reasonable, we are subject to audit by the Internal Revenue Service, in the United States, HM Revenue and Customs in the United Kingdom, state tax authorities in the states in which we operate, and other similar tax authorities in international jurisdictions. We have been subject to audits and challenges from applicable federal, state, or foreign tax authorities in the past, and may be subject to similar audits and challenges in the future. While we believe we comply with all applicable tax laws, rules, and regulations in the relevant jurisdictions, tax authorities may elect to audit us and determine that we owe additional taxes, which could result in a significant increase in our liabilities for taxes, interest, and penalties in excess of our accrued liabilities.
New tax legislative initiatives may be proposed from time to time, such as proposals for comprehensive tax reform in the United States, which may impact our effective tax rate and which could adversely affect our tax positions or tax liabilities. Our future effective tax rate could be adversely affected by, among other things, changes in the composition of earnings in jurisdictions with differing tax rates, changes in statutory rates and other legislative changes, changes in interpretations of existing tax laws, or changes in determinations regarding the jurisdictions in which we are subject to tax. From time to time, U.S. federal, state and local, and foreign governments make substantive changes to tax rules and their application, which could result in materially higher taxes than would be incurred under existing tax law and which could adversely affect our financial condition or results of operations.
Risks Related to Our Intellectual Property and Technology
Disruptions to our information technology systems, including failure to prevent outages, maintain security, and prevent unauthorized access to our information technology systems and other confidential information, could disrupt our business and materially and adversely affect our reputation, consolidated results of operations, and financial condition.
Information availability and security risks for online commerce companies have significantly increased in recent years because of, in addition to other factors, the proliferation of new technologies, the use of the internet and telecommunications technologies to conduct financial transactions, and the increased sophistication and activities of organized crime, hackers, terrorists, and other external parties. These threats may derive from fraud or malice on the part of third parties or current or former employees. In addition, human error or accidental technological failure could make us vulnerable to information technology system disruptions and/or cyber-attacks, including the introduction of malicious computer viruses or code into our system, phishing attacks, ransomware attacks, or other cyber security incidents. For example, in March 2023, one of our immaterial subsidiaries suffered a ransomware attack. Although the impacted subsidiary successfully maintained its operations during this event and the attack did not affect the rest of our business, future cyber-attacks could result in material adverse impacts to our business and our consolidated results of operations.
Our operations rely on the secure processing, transmission, and storage of confidential, proprietary and other information in our computer systems and networks. Our customers and other parties in the payments value chain rely on our digital technologies, computer and email systems, software, and networks to conduct their operations. In addition, to access our products and services, our customers increasingly use personal smartphones, tablet PCs, and other mobile devices that may be beyond our control.
Information technology system disruptions, cyber-attacks, ransomware attacks, or other cyber security incidents could materially and adversely affect our reputation, operating results, or financial condition by, among other things, making our auction platform inoperable for a period of time, damaging our reputation with buyers, sellers, and insurance companies as a result of the unauthorized disclosure of confidential information (including account data information), or resulting in governmental investigations, litigation, liability, fines, or penalties against us. If such attacks are not detected immediately, their effect could be compounded. While we maintain insurance coverage that may, subject to policy terms and conditions, cover certain aspects of these cyber risks, an insurer may deny or exclude from coverage certain types of claims or our insurance coverage may be insufficient to cover all losses and would not remedy damage to our reputation.
We regularly evaluate and implement new technologies and processes to manage risks relating to cyber-attacks and system and network disruptions, including but not limited to usage errors by our employees, power outages, and catastrophic events such as fires, tornadoes, floods, hurricanes, and earthquakes. We have also enhanced our security protocols based on the investigation we conducted and in response to our prior attacks and service interruptions. Nevertheless, we cannot provide assurances that our efforts to address cyber security incidents and mitigate against the risk of future cyber security incidents or system disruptions will be successful. The techniques used by criminals to obtain unauthorized access to sensitive data change frequently and are often not recognized immediately. For example, as AI technologies, including generative AI models, develop rapidly, threat actors are using these technologies to create new sophisticated attack methods that are increasingly automated, targeted and coordinated and more difficult to defend against. We may be unable to anticipate these techniques or implement adequate preventative measures and believe that cyber-attacks and threats against us have occurred in the past and are likely to continue in the future. If our systems are compromised, become inoperable for extended periods of time, or cease to function properly, we may have to make a significant investment to fix or replace them, and our ability to provide many of our electronic and online solutions to our customers may be impaired. In the event of another, more serious ransomware attack, we could suffer significant financial and reputational harm, regardless of whether we choose to pay the ransom amount. In addition, as cyber-threats continue to evolve, we may be required to expend significant additional resources to continue to