PRGS 10-K & 10-Q changes, risk factors and insider trading
Progress Software Corp. · Nasdaq · Services-Prepackaged Software · CIK 876167 · All filings on SEC.gov
At a glance
What changed in the latest 10-K
Risk Factors
Largest changes
If our security measures are breached, our products and services may be perceived as not being secure, customers may curtail or stop using our products and services, and we may incur significant legal and financialsee in full comparisonexposure, including but not limited toexposure from loss of customer or company data, loss ofcustomerscustomers, or otherwise. Ourproductsbusinessand services involverequires the storage and transmission of ourcustomers’proprietary information and customer information within Progress' enterprise information technology systems, which may be vulnerable to unauthorized access,computer viruses, cyber-attacks,distributed denial of serviceattacksattacks, and otherdisruptive problems.cyber-attacks. Individual and groups of hackers and sophisticated organizations, including state-sponsored organizations or nation-states, continuously undertake attacks that pose threats to our customers and our software products, and we have experienced cybersecurity incidents in which such actors have gained unauthorized access to our IT systems and data, including customer systems and data. For example, as disclosed on December 19, 2022, following the detection of irregular activity on certain portions of our corporate network, we engaged outside cybersecurity experts and other incident response professionals to conduct a forensic investigation and assess the extent and scope of the cyber incident (the "November 2022 Cyber Incident"). During the investigation, we and our external advisors uncovered evidence of unauthorized access to our corporate network, including evidence that certaincompanyCompany data had been exfiltrated. As demonstrated by the November 2022 Cyber Incident, due to the actions of outside parties, employee error, malfeasance, or otherwise, an unauthorized party may obtain access to our data or ourcustomers’customers' data, which could result in its theft, destruction,corruptioncorruption, or misappropriation and thus legal and financial exposure. Security risks in recent years have increased significantly given the increased sophistication and activities of hackers, organized crime, including state-sponsored organizations and nation-states, and other outside parties.Cyber threats are continuously evolving, increasing the difficulty of defending against them. Increased risks of such attacks and disruptions also exist due to the Russian invasion of Ukraine beginning in February 2022. While we have implemented security procedures and controls aimed at addressing these threats, our security measures could be compromised, could prove to be inadequate or could fail. Any security breach or unauthorized access could result in significant legal and financial exposure, increased costs to defend litigation, indemnity and other contractual obligations, government fines and penalties, damage to our reputation and our brand, and a loss of confidence in the security of our products and services that could potentially have an adverse effect on our business and results of operations. Breaches of our network could disrupt our internal systems and business applications, including services provided to our customers. Additionally, data breaches could compromise technical and proprietary information, harming our competitive position. We may need to spend significant capital or allocate significant resources to protect against the threat of security breaches or to address security related concerns. If an actual or perceived breach of our security occurs, the market perception of the effectiveness of our security measures could be harmed and we could lose customers. In addition, our insurance coverage may not be adequate to cover all costs related to cybersecurity incidents and the disruptions resulting from such events.
“Cyber threats are continuously evolving, including through the utilization of AI, increasing the difficulty of defending against them. While we have implemented security procedures and controls aimed at addressing these threats, our security measures could be compromised, could prove to be inadequate, or could fail. …”see in full comparison
Our international operations expose us to additional risks, and changes in global economic and political conditions could adversely affect our international operations, oursee in full comparisonrevenuerevenue, and our net income. Approximately41%36% of our total fiscal20242025 revenue was generated from sales outside North America. Political and/or financial instability,oiltariffs,pricetheshocksimpositionandof import/export controls, or armed conflict in various regions of theworld, including, but not limited to, Russia/Ukraine conflict and the armed conflicts involving Israel,world can lead to economic uncertainty and may adversely impact our business. Political instability may lead to significant, continuing volatility in global stock markets and currency exchange rate fluctuations. Ifcustomers’customers' buying patterns, decision-making processes, timing of expecteddeliveriesdeliveries,andor timing of new projects unfavorably change due to economic or political conditions, therewouldcould be a material adverse effect on our business, financialconditioncondition, and operating results.
“In addition to the above, and as disclosed in prior filings, we received a subpoena from the SEC’s Division of Enforcement on October 2, 2023, as part of a fact-finding inquiry seeking various documents and information relating to the MOVEit Vulnerability. In a letter dated August 7, 2024, the SEC notified us that it had concluded its investigation and did not intend to recommend an enforcement action against us (the "Termination Letter"). The Termination Letter was provided under the guidelines set out in the final paragraph of Securities Act Release No. 5310.”see in full comparison
“We have also been cooperating with inquires and investigations from: (i) several domestic and foreign data privacy regulators (as of the date of this filing, we have assisted with all inquiries and investigations, a number of which have been formally closed without regulatory action), (ii) several state attorneys general (as of the date of this filing, we have assisted with all inquiries and investigations, and are not aware of any enforcement or regulatory actions directed against Progress), (iii) a U.S. …”see in full comparison
“The claims and investigations described above may have an adverse effect on how we operate our business and our results of operations, and in the future, we may be subject to additional governmental or regulatory investigations, as well as additional litigation or indemnification claims related to the MOVEit Vulnerability. Following the discovery of the MOVEit Vulnerability and the various remedial actions previously described, we have discovered and patched additional vulnerabilities within the MOVEit Transfer and MOVEit Cloud platforms. …”see in full comparison
Full comparison: every changed paragraph (69)
Technology and customer requirements evolve rapidly in our industry, and if we do not continue to develop or acquire new products and enhance our existing products in response to these changes, our business could be harmed. The markets for our products are characterized by rapid technological advancement, including the introduction of new technologies such as AI. Ongoing enhancements to our product sets (both organically and through acquisitions) will be required to enable us to maintain our competitive position and the competitive position of our ISVs, distributors/resellers, and OEMs. We may not be successful in developing and marketing enhancements to our products on a timely basis, and any enhancements we develop may not adequately address the changing needs of the marketplace. Overlaying the risks associated with our existing products and enhancements are ongoing technological developments and rapid changes in customer and partner requirements. Our future success will depend upon our ability to develop, acquire and introduce new products in a timely manner that take advantage ofleverage technological advancesadvances, including AI, and respond to new customer and partner requirements. We may not be successful in developing or acquiring new products incorporatingthat incorporate new technologytechnologies on a timely basis, and any new products we develop or acquire may not adequately address the changing needs of theour marketplacecustomers or may not be accepted by the market. Failure to develop new products and product enhancements that meet market needs in a timely manner could have a material adverse effect on our business, financial conditioncondition, and operating results.
We may not be successful in our artificial intelligence initiatives, which could adversely affect our business, reputation, or financial results. We have made, and expect to continue to make, investments to integrate AI into our products and update our products to enable our customers to use AI for insights, digital experiences, and applications, as well as to use AI to enhance our own engineering and business operations. Such integration and use of AI may become more important in our product offerings and operations over time. Our AI efforts may not be successful and our competitors or other third parties may incorporate AI into their offerings more successfully and efficiently than we do and achieve greater and faster adoption, which could impair our ability to compete effectively and adversely affect our business and financial results. In addition, given the rapidly developing nature of AI, we may fail to adequately adopt and adapt to technological advancements, which may have a negative impact on our product development capabilities and adversely affect our business and financial results.
We are substantially dependent on our OpenEdge and ShareFile products. We derive a significant portion of our revenue from software license and maintenance revenue attributable to our OpenEdge product set, as well as SaaS revenue attributable to our ShareFile product set, which in fiscal year 20242025 together accounted for approximatelyslightly 34%more than half of our aggregate revenue on a consolidated basis. Accordingly, our future results depend on continued market acceptance of OpenEdge.OpenEdge and ShareFile. If consumer demand declines, or new technologies emerge that are superior to, or are more responsive to customer requirements thanthan, OpenEdge,OpenEdge or ShareFile, such that we are unable to maintain OpenEdge’sthese products' competitive position within itstheir marketplace,respective marketplaces, our business, financial conditioncondition, and operating results may be materially adversely affected.
The segments of the software industry in which we participate are intensely competitive, and our inability to compete effectively could harm our business. We experience significant competition from a variety of sources with respect to the marketing and distribution of our products. Many of our competitors have greater financial, marketingmarketing, or technical resources than we do and may be able to adapt more quickly to new or emerging technologies and changes in customer requirementsrequirements, or to devote greater resources to the promotion and sale of their productsproducts, than we can. Increased competition could make it more difficult for us to maintain our market presence or lead to downward pricing pressure. In addition, current and potential competitors may make strategic acquisitions or establish cooperative relationships among themselves or with third parties, thereby increasing their ability to deliver products that better address the needs of our existing or prospective customers. Current and potential competitors may also be more successful than we are in having their products or technologies widely accepted. We may be unable to compete successfully against current and future competitors, and our failure to do so could have a material adverse effect on our business, prospects, financial conditioncondition, and operating results.
The value of our Chef software assets may be limited by open source development and licensing practices. Our Chef offerings incorporate software components licensed to the general public under open source licenses. We obtain many components from software developed and released by contributors to independent open source components of our offerings. One of the characteristics of open source software is that the governing license terms generally allow liberal modifications of the code and distribution to a wide group of companies and/or individuals. As a result, the marketplace for new products is intensely competitive and characterized by low barriers to entry because others could develop new software products or services based upon those open source programs that compete with existing open source software that we support and incorporate into our Chef products. New competitors that develop their own open source software or hybrid proprietary and open source software offerings with technological, marketingmarketing, or other competitive advantages may reduce the demand for and impose price pressure on our products, enabling them to rapidly acquire market share and limit the value of our software assets.
We intend to make additional acquisitions of businesses, productsproducts, or technologies that involve additional risks, which could disrupt our business or harm our financial condition, results of operationsoperations, or cash flows. A key element of our total growth strategy includes the acquisition of businesses that offer complementary products, servicesservices, and technologies, augment our revenues and cash flows, and meet our strict financial and other criteria. We may not be able to identify suitable acquisition opportunities or consummate any such transactions on favorable terms or at all. Even if an acquisition is successful, the integration of a new business involves a number of risks that could have a material adverse effect on our business, financial condition, operating resultsresults, or cash flows, including:
•difficulties of assimilating the operations and personnel, productsproducts, or systems of acquired companies;
Difficulties associated with any acquisitions we may pursue, and their integrationintegration, may be complicated by factors such as:
•lack of experience operating in the industry or markets of the acquired business (e.g., satisfying the highly technical requirements of public-sectorgovernment and other quasi-public-sector customers);
•the potential for deficiencies in internal controls at the acquired or combined business, including but not limited to with regard to any weaknesses or vulnerabilities in the acquired company’scompany's cybersecurity controls;
In addition, if we fail to complete an announced acquisition, the market price of our common stock could fall to the extent such price reflects an assumption that such acquisition will be completed, and we may incur significant unrecoverable costs. Further, the failure to consummate an acquisition may result in negative publicity and adversely impact our relationships with our customers, vendorsvendors, and employees. We may become subject to legal proceedings relating to thean acquisitionacquisition, and the integration of an acquired businessesbusiness may not be successful. Failure to manage and successfully integrate an acquired businesses,business, achieve anticipated levels of profitability of thean acquired business, improve margins of thean acquired businessesbusiness and its products, or realize other anticipated benefits of an acquisition could materially harm our business, operating resultsresults, and margins.
Adverse developments in our relationships with sales channel partners could harm our revenues and results of operations. We recognize a substantial portion of our revenue from sales made through third parties, including our ISVs, distributors/resellers, and OEMs, and our future results depend in large part upon our continued successful distribution of our products through these channels. The activities of these third parties are not within our direct control. Our failure to manage our relationships with these third parties effectively could impair the success of our sales, marketing, and support activities. A reduction in the sales efforts, technical capabilities, or financial viability of these parties, a misalignment of interest between us and them, or a termination of our relationship with a major ISV, distributor/reseller, or OEM could have an adverse effect on our sales and financial results. Any adverse effect on any of our ISVs', distributors'/resellers', or OEMs' businesses related to competition, pricing, and other factors could also have a material adverse effect on our business, financial condition, and operating results.
Our international operations expose us to additional risks, and changes in global economic and political conditions could adversely affect our international operations, our revenuerevenue, and our net income. Approximately 41%36% of our total fiscal 20242025 revenue was generated from sales outside North America. Political and/or financial instability, oiltariffs, pricethe shocksimposition andof import/export controls, or armed conflict in various regions of the world, including, but not limited to, Russia/Ukraine conflict and the armed conflicts involving Israel,world can lead to economic uncertainty and may adversely impact our business. Political instability may lead to significant, continuing volatility in global stock markets and currency exchange rate fluctuations. If customers’customers' buying patterns, decision-making processes, timing of expected deliveriesdeliveries, andor timing of new projects unfavorably change due to economic or political conditions, there wouldcould be a material adverse effect on our business, financial conditioncondition, and operating results.
•longer payment cycles and credit and collectability risk on our accounts receivables;
•longer payment cycles;
•credit risk and higher levels of payment fraud;
•greater difficulties in accounts receivable collection;
•varying regulatory and legal requirementsrequirements, including international trade and labor laws;
•compliance with international and local trade, labor and export control laws;
•management of our international operations, including increased administrative and compliance expenses, geographical distance, and language and cultural differences;
•difficulties in developing, staffing, and simultaneously managing a large number of varying foreign operations as a result of distance, legal impediments and language and cultural differences;
•reduceddifficulties orin minimalenforcing protectioncontractual ofand intellectual property rights in some countries;
•changes in U.S. or foreign trade policies or practices that increase costs or restrict the distribution of products;
•economic instability in emerging markets; and
•regional or global health crises; and
Any one or more of these factors could have a material adverse effect on our international operations, and, consequently, on our business, financial conditioncondition, and operating results.
In addition, our business has been, and could in the future be, adversely affected by regional or global health crises. A significant outbreak of contagious diseases, other adverse public health developments, or the fear of such events that results in a widespread health crisis could adversely affect global supply chains and the economies and financial markets of many countries. Any prolonged economic disruption could affect demand for our products and services and adversely impact our business, financial condition and results of operations.
If our security measures are breached, our products and services may be perceived as not being secure, customers may curtail or stop using our products and services, and we may incur significant legal and financial exposure, including but not limited toexposure from loss of customer or company data, loss of customerscustomers, or otherwise. Our productsbusiness and services involverequires the storage and transmission of our customers’ proprietary information and customer information within Progress' enterprise information technology systems, which may be vulnerable to unauthorized access, computer viruses, cyber-attacks, distributed denial of service attacksattacks, and other disruptive problems.cyber-attacks. Individual and groups of hackers and sophisticated organizations, including state-sponsored organizations or nation-states, continuously undertake attacks that pose threats to our customers and our software products, and we have experienced cybersecurity incidents in which such actors have gained unauthorized access to our IT systems and data, including customer systems and data. For example, as disclosed on December 19, 2022, following the detection of irregular activity on certain portions of our corporate network, we engaged outside cybersecurity experts and other incident response professionals to conduct a forensic investigation and assess the extent and scope of the cyber incident (the "November 2022 Cyber Incident"). During the investigation, we and our external advisors uncovered evidence of unauthorized access to our corporate network, including evidence that certain companyCompany data had been exfiltrated. As demonstrated by the November 2022 Cyber Incident, due to the actions of outside parties, employee error, malfeasance, or otherwise, an unauthorized party may obtain access to our data or our customers’customers' data, which could result in its theft, destruction, corruptioncorruption, or misappropriation and thus legal and financial exposure. Security risks in recent years have increased significantly given the increased sophistication and activities of hackers, organized crime, including state-sponsored organizations and nation-states, and other outside parties. Cyber threats are continuously evolving, increasing the difficulty of defending against them. Increased risks of such attacks and disruptions also exist due to the Russian invasion of Ukraine beginning in February 2022. While we have implemented security procedures and controls aimed at addressing these threats, our security measures could be compromised, could prove to be inadequate or could fail. Any security breach or unauthorized access could result in significant legal and financial exposure, increased costs to defend litigation, indemnity and other contractual obligations, government fines and penalties, damage to our reputation and our brand, and a loss of confidence in the security of our products and services that could potentially have an adverse effect on our business and results of operations. Breaches of our network could disrupt our internal systems and business applications, including services provided to our customers. Additionally, data breaches could compromise technical and proprietary information, harming our competitive position. We may need to spend significant capital or allocate significant resources to protect against the threat of security breaches or to address security related concerns. If an actual or perceived breach of our security occurs, the market perception of the effectiveness of our security measures could be harmed and we could lose customers. In addition, our insurance coverage may not be adequate to cover all costs related to cybersecurity incidents and the disruptions resulting from such events.
Cyber threats are continuously evolving, including through the utilization of AI, increasing the difficulty of defending against them. While we have implemented security procedures and controls aimed at addressing these threats, our security measures could be compromised, could prove to be inadequate, or could fail. Any security breach or unauthorized access could result in significant legal and financial exposure, increased costs to defend litigation, indemnity and other contractual obligations, government fines and penalties, damage to our reputation and our brand, and a loss of confidence in the security of our products and services that could potentially have an adverse effect on our business and results of operations. Breaches of our network could disrupt our internal systems and business applications, including services provided to our customers. Additionally, data breaches could compromise technical and proprietary information, harming our competitive position. We may need to spend significant capital or allocate significant resources to protect against the threat of security breaches or to address security related concerns. If an actual or perceived breach of our security occurs, the market perception of the effectiveness of our security measures could be harmed and we could lose customers. In addition, our insurance coverage may not be adequate to cover all costs related to cybersecurity incidents and the disruptions resulting from such events.
If our products contain software defects or security flaws, it could harm our revenues by causing us to lose customers and could increase our liabilities by exposing us to costly governmental investigations or litigation. For example, the exploitation of the zero-day MOVEit Vulnerability in May 2023 has resulted in informal government inquiries, three formal government investigations, and private litigation. Our products, despite extensive testing and quality control, may, and at times do, contain defects, vulnerabilitiesvulnerabilities, or security flaws. In the ordinary course of business, we may need to issue corrective releases of our software products to fix any defects, vulnerabilities, or security flaws. Depending upon the severity of any such matters, the detection and correction of such matters can be time consuming and costly. If any such issues are exploited by malicious threat actors, we could experience, among other things, a material adverse impact to our revenues due to loss of customers and increased liabilities due to costly governmental investigations or litigation. In addition, any such matters could affect the ability of our products to work with hardware or other software products, delay the development or release of new products or new versions of products (due to a reallocation of our internal resources), and/or adversely affect market acceptance of our products, all of which could have a material adverse effect on our operating results and cash flows.
As previously disclosed, on the evening of May 28, 2023, we learned that our MOVEit Transfer (the on-premise version) and MOVEit Cloud (a cloud-hosted version of MOVEit Transfer) products were attacked via a "zero-day vulnerability" that could provide for unauthorized escalated privileges and access to the customer’scustomer's underlying environment (the "MOVEit Vulnerability"). A "zero-day vulnerability" is a vulnerability that has been publicly disclosed and/or exploited (e.g., by an independent researcher or threat actor) before the software vendor has an opportunity to patch it. We continue to monitorFollowing the impactdiscovery of the MOVEit Vulnerability onand ourthe business,various operations,remedial actions previously described, we discovered and financialpatched results.additional vulnerabilities within the MOVEit Transfer and MOVEit Cloud representedplatforms. lessWhile thanwe 4%are incurrently aggregatenot aware of any evidence that these additional vulnerabilities were exploited by malicious threat actors, we cannot guarantee that we have or will uncover and/or address all vulnerabilities within the MOVEit platform or any of our revenueother forproducts theprior fiscalto yearexploitation endedby Novemberthreat 30, 2024.actors.
As a result of the MOVEit Vulnerability, we are party to certain class action lawsuits filed by individuals who claim to have been impacted by the exfiltration of data from the environments of our MOVEit Transfer customers, which the Judicial Panel on Multidistrict Litigation transferred to the District of Massachusetts for coordinated and consolidated proceedings (the "MDL"). The MDL has also consolidated the previously disclosed insurance subrogation claimcomplaint (where an insurer is seeking recovery for expenses incurred on behalf of its insured in connection with the MOVEit Vulnerability) and, as of the date of this filing, one customer cross-claim.
As previously disclosed, we have also cooperated with inquiries and investigations from various domestic and foreign governmental authorities (data privacy regulators, a U.S. federal law enforcement agency, the Federal Trade Commission, and the SEC), a number of which have been formally closed and, as the date of this filing, have not resulted in any prosecution or enforcement actions against us. We have also supported inquiries and investigations from several state attorneys general, one of which has been formally closed without any enforcement or regulatory actions directed against us.
We have also been cooperating with inquires and investigations from: (i) several domestic and foreign data privacy regulators (as of the date of this filing, we have assisted with all inquiries and investigations, a number of which have been formally closed without regulatory action), (ii) several state attorneys general (as of the date of this filing, we have assisted with all inquiries and investigations, and are not aware of any enforcement or regulatory actions directed against Progress), (iii) a U.S. federal law enforcement agency (as of the date of this filing, we have assisted with all inquiries under this investigation and this is not an enforcement action or formal governmental investigation targeting Progress), and (iv) on December 21, 2023, we received a preservation notice from the Federal Trade Commission (the "FTC"), but have not otherwise received a request for information, nor is Progress aware of any formal FTC investigation.
In addition to the above, and as disclosed in prior filings, we received a subpoena from the SEC’s Division of Enforcement on October 2, 2023, as part of a fact-finding inquiry seeking various documents and information relating to the MOVEit Vulnerability. In a letter dated August 7, 2024, the SEC notified us that it had concluded its investigation and did not intend to recommend an enforcement action against us (the "Termination Letter"). The Termination Letter was provided under the guidelines set out in the final paragraph of Securities Act Release No. 5310.
Our financial liability arising from any of the foregoingMOVEit Vulnerability will depend on many factors, including the progression of the MDL and additional litigation or indemnification claims, and any settlements resulting from remaining or additional governmental or regulatory investigations; therefore, we are unable at this time to estimate the quantitative impact of any such liability with any reasonable degree of certainty. As our litigation response continues, we will continue to assess the potential impact of the MOVEit Vulnerability on our business, operations, and financial results.
The claims and investigations described above may have an adverse effect on how we operate our business and our results of operations, and in the future, we may be subject to additional governmental or regulatory investigations, as well as additional litigation or indemnification claims related to the MOVEit Vulnerability. Following the discovery of the MOVEit Vulnerability and the various remedial actions previously described, we have discovered and patched additional vulnerabilities within the MOVEit Transfer and MOVEit Cloud platforms. While we are currently not aware of any evidence that these additional vulnerabilities were exploited by malicious threat actors, we cannot guarantee that we have or will uncover and/or address all vulnerabilities within the MOVEit platform or any of our other products prior to exploitation by threat actors.
Our business could be damaged, and we could be subject to liability, in the event of any unauthorized access to our data or our customers’customers' data, including through privacy and data security breach. The use of certain of our products, including MOVEit Cloud and ShareFile, involves the transmission or storage of third-party data in our environment, some of which may be considered personally identifiable, confidential, or sensitive. In the ordinary course of business, we face security threats from malicious threat actors that could obtain unauthorized access to our systems, infrastructure, products, and networks. We anticipate that these threats will continue to grow in scope and complexity over time, particularly as the use of AI by malicious threat actors increases, we acquire new productsproducts, and a larger proportion of our revenues derive from products that transmit or store sensitive data.
While we endeavor to continue mitigating security risks for our products, malicious threat actors might use techniques to exploit other zero-day vulnerabilities or use other means that we are unable to defend against,against in order to compromise and infiltrate our systems, infrastructure, networks, and products, including, but not limited to,to MOVEit, ShareFileMOVEit or other products.ShareFile.
While we devote significant resources to cyber securitycybersecurity related matters in the operation of our business, we may fail to detect the existence of a breach and be unable to prevent unauthorized access to user and company content across our systems, infrastructure, products, and networks. The techniques used to obtain unauthorized access, disable or degrade service, or sabotage systems change frequently and are often not recognized until launched against a target. They may originate from less regulated or remote areas around the world, or from state-sponsored actors. If our security measures are breached, we may suffer reputational damage, our products may be perceived as insecure, and we may lose existing customers or fail to attract and retain new customers.
A failure of our information technology systems, including a cyber incident, could have a material adverse effect on our business. We rely on our technology infrastructure, and the technology infrastructure of third parties, for many functions, including selling our products, supporting our ISVs and other third-party channels, fulfilling orders and billing, and collecting and making payments. This technology infrastructure may be vulnerable to damage or interruption from natural disasters, power loss, telecommunication failures, terrorist attacks, the outbreak of wars or other armed conflicts, the escalation of hostilities, geopolitical tensions or trade wars, acts of terrorism or "acts of God," particularly involving geographies in which we or third parties on whom we depend have operations, computer intrusions or other similar cyber intrusions, vulnerabilities and viruses, software errors, computer denial-of-service attacksattacks, and other similar events. A significant number of the systems making up this infrastructure are not redundant, and our disaster recovery planning may not be sufficient for every eventuality. This technology infrastructure may fail or be vulnerable to damage or interruption because of actions by third parties or employee error or malfeasance. In addition, depending upon the severity of any such actions, we may not carry business interruption insurance sufficient to protect us from all losses that may result from interruptions in our services as a result of such technology infrastructure failures or provide us with the ability to cover all contingencies. Any interruption in the availability of our websites and on-line interactions with customers or partners may cause a reduction in customer or partner satisfaction levels, which in turn could cause additional claims, reduced revenuerevenue, or loss of customers or partners. Despite any precautions we may take, these problems could result in, among other consequences, a loss, destruction, corruption or misappropriation of company or customer data, loss of confidence in the stability and reliability of our offerings, damage to our reputation, and legal liability, all of which may adversely affect our business, financial condition, operating results and cash flows.
Integration of artificial intelligence into our product offerings and our use of artificial intelligence in our operations could result in reputational or competitive harm, legal liability, and other adverse effects on our business. We have integrated, and plan to further integrate, artificial intelligence (“AI”) capabilities into certain components of product offerings, and we use and expect to increase the use of AI in our operations. Such integration and use of AI may become more important in our product offerings and operations over time. These AI-related initiatives, whether successful or not, could cause us to incur substantial costs and could result in delays in our software release cadence. Our competitors or other third parties may incorporate AI into their products or operations more quickly or more successfully than we do, which could impair our ability to compete effectively. Additionally, AI algorithms may be flawed and datasets underlying AI algorithms may be insufficient or contain biased information. If the AI tools integrated into our products or that we use in our operations produce analyses or recommendations that are or are alleged to be deficient, inaccurate, or biased, our reputation, business, financial condition, and results of operations may be adversely affected.
Other companies have experienced cybersecurity incidents that implicate confidential and proprietary company data and/or the personal data of end users of AI applications integrated into their software offerings or used in their operations. If we were to experience a cybersecurity incident related to the integration of AI capabilities into our product offerings or our use of AI applications in our operations, our business and results of operations could be adversely affected. AI also presents various emerging legal, regulatory and ethical issues, and the incorporation of AI into our product offerings and our use of AI applications in our operations could require us to expend significant resources in developing, testing and maintaining our product offerings and may cause us to experience brand, reputational, or competitive harm, or incur legal liability. OnAny Octoberlegislation 30, 2023, the Biden administration issued an Executive Order to, among other things, establish extensive new standards forconcerning AI safetyadopted and security. Other jurisdictions may decide to adopt similardomestically or more restrictive legislation that may render the use of such technologies challenging. These restrictionsglobally may make it harder for us to conduct our business using AI, lead to regulatory fines or penalties, require us to change our product offerings or business practices, or prevent or limit our use of AI.
Catastrophic events, including but not limited to cyber events, may disrupt our business. We rely on our network infrastructure and enterprise applications, internal technology systemssystems, and websitewebsites for our development, marketing, operations, supportsupport, and sales activities. In addition, we rely on third-party hosted services, and we do not control the operation of third-party data center facilities, which increases our vulnerability. A disruption, infiltration or failure of these systems or third-party hosted services in the event of a major earthquake, fire, flood, tsunami or other weather event, power loss, telecommunications failure, software or hardware malfunction, pandemic, cyber-attack or other similar interruption to our business, war, terrorist attackattack, or other catastrophic event that our disaster recovery plans do not adequately address, could cause system interruptions, reputational harm, loss of intellectual property, delays in our product development, lengthy interruptions in our services, breaches of data security and loss, destruction, misappropriationmisappropriation, or corruption of critical company or customer data. A catastrophic event that results in the loss, destruction, misappropriation, corruption or disruption of any of our data, our customers’customers' datadata, or our data centers or our critical business or information technology systems could severely affect our ability to conduct normal business operations and, as a result, our future operating results could be adversely affected, and the adverse effects of any such catastrophic event would be exacerbated if experienced at the same time as another unexpected and adverse event.
We also depend on third-party service providers to provide the data centers and other infrastructure necessary to certain of our products. Any disruption in the services provided by these third parties or any failure to renew the services could adversely affect the performance of products or result in a loss of user content, resulting in harm to our business and reputation. Customers rely on certain of our products to transfer or process their content. The infrastructure on which our products rely may not be adequately designed with sufficient reliability and redundancy to avoid performance delays or outages and/or may not be scalable to meet increasing user demands. If our products are unavailable when users attempt to access them, or if the products do not load or perform as quickly as users expect, they may decrease or discontinue their use of our products, which could be harmful to our business, results of operations, and financial condition. Our third-party service providers along with their datacentersdata centers and other facilities are also vulnerable to damage or interruption from human error, intentional bad acts, security breachesbreaches, and other catastrophic events, any of which could disrupt the availability of our products and/or compromise or destroy user content, which could be harmful to our business, results of operations, and financial condition.
We have relationships with third parties to provide, develop, and create applications that integrate with certain of our products, and our business could be harmed if we are unable to continue these relationships. We use software and services licensed and procured from third parties. We may need to obtain additional licenses and services from third parties to utilize the intellectual property and technology associated with the development of our products, which might not be available to us on acceptable terms, or at all. Any loss of the right to use any software or services required for the development and maintenance of our products could harm our business. Any errors or defects in third-party software or services could result in errors or a failure of our products, which could harm our business, results of operations, and financial condition.
Adverse developments in our relationships with sales channel partners could harm our revenues and results of operations. We recognize a substantial portion of our revenue from sales made through third parties, including our ISVs, distributors/resellers, and OEMs, and our future results depend in large part upon our continued successful distribution of our products through these channels. The activities of these third parties are not within our direct control. Our failure to manage our relationships with these third parties effectively could impair the success of our sales, marketing and support activities. A reduction in the sales efforts, technical capabilities or financial viability of these parties, a misalignment of interest between us and them, or a termination of our relationship with a major ISV, distributor/reseller, or OEM could have an adverse effect on our sales and financial results. Any adverse effect on any of our ISV's, distributors'/resellers', or OEMs’ businesses related to competition, pricing and other factors could also have a material adverse effect on our business, financial condition and operating results.
We rely on the experience and expertise of our skilled employees, and must continue to attract and retain qualified technical, marketing and managerial personnel in order to succeed. Our future success will depend in large part upon our ability to attract and retain highly skilled technical, managerial, salessales, and marketing personnel. There is significant competition for such personnel in the software industry. We may not continue to be successful in attracting and retaining the personnel we require to develop new and enhanced products and to continue to grow and operate profitably.
We are subject to risks associated with compliance with laws and regulations globally, which may harm our business. We are a global company subject to varied and complex laws, regulationsregulations, and customs, both domestically and internationally. These laws and regulations relate to many core aspects of our business, including data privacy or related privacy practices, AI, corporate governance, securities regulations, anti-trust and competition, anti-corruption, sanctions and trade protection, and import and export control. The application of these laws and regulations to our business is often unclear and may at times conflict on a domestic or international basis. For example, data privacy and AI regulations are evolving rapidly in many jurisdictions, often with extremely punitive penalties. Compliance with these laws and regulations may involve significant costs or require changes in our business practices that result in reduced revenue and profitability. Non-compliance could also result in fines, damages, criminal sanctions against us, our officers or our employees, prohibitions on the conduct of our business, and damage to our reputation.
Our business practices with respect to the collection, useuse, and management of personal information could give rise to operational interruption, liabilitiesliabilities, or reputational harm as a result of governmental regulation, legal requirementsrequirements, or industry standards relating to consumer privacy and data protection. As regulatory focus on privacy issues continues to increase and worldwide laws and regulations concerning the handling of personal information expand and become more complex, potential risks related to data collection and use within our business will intensify. For example, the regulatory environment applicable to the handling of the European Economic Area ("EEA") residents' personal data, which is governed by the General Data Protection Regulation of 2018 ("GDPR") and/or respectively the national data protection laws of United Kingdom, Switzerland, and other countries in which we operate, may cause us to assume additional liabilities, obligations or incur additional costs, and could result in our business, operating results and financial condition being harmed. Additionally, we and our customers may face a risk of enforcement actions by the competent data protection authorities relating to personal data transfers to us and by us from the EEA and other jurisdictions which have country specific data transfer requirements. Any such enforcement actions could result in substantial costs and diversion of resources, distract management and technical personnel and adversely affect our business, operating results and financial condition.
In addition, governmental entities in the U.S. and other countries have enacted or are considering enacting legislation or regulations or may in the near future interpret existing legislation or regulations, in a manner that could significantly impact our ability and the ability of our customers and data partners to collect, augment, analyze, use, transfertransfer, and share personal and other information that is integral to certain business functions. For example, U.S.approximately states like Texas and Oregon enacted data privacy laws that took effect in 2024, both of which expanded the consumer's privacy rights and the obligations to the organizations doing business in those states. Othertwenty U.S. state legislatures have also implemented varying privacy laws and regulations, or are considering implementing legislation that we expect to become effective in the near term. Moreover, several privacy bills are under congressional review at the U.S. federal level.
We could incur substantial costcosts in protecting our proprietary software technologytechnology, and if we fail to protect our technology,technology we could incur material harm to our business. We rely principally on a combination of contract provisions and copyright, trademark, patentpatent, and trade secret laws to protect our proprietary technology. Despite our efforts to protect our proprietary rights, unauthorized parties may attempt to copy aspects of our products or to obtain and use information that we regard as proprietary. Policing unauthorized use of our products is difficult. Litigation may be necessary in the future to enforce our intellectual property rights, to protect our trade secretssecrets, or to determine the validity and scope of the proprietary rights of others. This litigation could result in substantial costs and diversion of resources, whether or not we ultimately prevail on the merits. The steps we take to protect our proprietary rights may be inadequate to prevent misappropriation of our technology; moreover, others could independently develop similar technology.
Weakness in the U.S. and international economies may result in fewer sales of our products and may otherwise harm our business. We are subject to risks arising from adverse changes in global economic conditions, especially those in the U.S., Europe and Latin America. If global economic conditions weaken, credit markets tighten and/or financial markets become unstable, customers may delay, reduce or forego technology purchases, both directly and through our ISVs, resellers/distributors and OEMs. This could result in reductions in sales of our products, longer sales cycles, slower adoption of new technologiestechnologies, and increased price competition. Further, deteriorating economic conditions could adversely affect our customers and their ability to pay amounts owed to us (see Our customers and partners may seek refunds, delay implementation timelines, delay payment, fail to pay us in accordance with the terms of their agreements, decline renewals or upgrades, or reduce or terminate use of our products, all of which can have an adverse effect on us). If the U.S. and other international economies experience inflationary pressures, our expenses (including the cost of labor) may increase, credit and securities markets may be adversely affected, and customer demand for our products and their ability to make payments may be impacted. Any of these events would likely harm our business, financial condition, and results of operations.
Fluctuations in foreign currency exchange rates or interest rates have had, and could continue to have, an adverse impact on our financial condition and results of operations. Changes in the value of foreign currencies relative to the U.S. dollarDollar and related changes in interest rates have adversely affected our results of operations and financial position in the past and could continue to do so.so again in the future. In recentthe periods,past, as the value of the U.S. dollarDollar has strengthened in comparison to certain foreign currencies (particularly in EMEA), our reported international revenue has been reduced because foreign currencies translate into fewer U.S. dollars.Dollars. As approximately one-third of our revenue is denominated in foreign currencies, these exchange rate fluctuations have impacted, and we expect will continue to impact, our revenue results. Please see Management’sManagement's Discussion and Analysis of Financial Condition and Results of Operations in Part II, Item 7 for additional information. We seek to reduce our exposure to fluctuations in exchange rates by entering into foreign exchange forward contracts to hedge certain actual and forecasted transactions of selected currencies (mainly in Europe, Brazil, India and Australia); however, our currency hedging transactions may not be effective in reducing the adverse impact of fluctuations in foreign currency exchange rates. Further, as geopolitical volatility around the world increases, there is increasing risk of the imposition of exchange or price controls, or other restrictions on the conversion of foreign currencies, which could have a material adverse effect on our business, financial condition and operating results.
Our stock price has been, and may continue to be, volatile, and your investment could lose value. Our revenue and quarterly results may fluctuate, which could adversely affect the market price of our common stock. We have experienced, and may in the future experience, significant fluctuations in our quarterly operating results that may be caused by manya factors.variety Theseof factorsfactors, includeincluding:
•the increasing prominence of new technologies, including AI, in the markets in which we compete;
•changes in the level of operating expenses, including unforeseen expenses incurred in connection with items such as cyber securitycybersecurity instances;
The market price of our common stock, like that of other technology companies, is volatile and is subject to wide fluctuations in response to quarterlya variationsvariety inof factors, including operating results, announcements of technological innovations or new products by us or our competitors,competitors; the proliferation and anticipated impact of AI on the technology sector; changes in financial estimates by securities analysts; purchases or sales of our stock by our officers or directors; repurchases of shares of our common stock; the issuance of additional shares or securities convertible into, or exchangeable or exercisable for, shares of our common stock, including upon the conversion of the Notes (as defined below) or under our equity compensation plans, general economic conditions and other macroeconomic factors; or other events or factors. The market price of our common stock may also be affected by broader market trends unrelated to our performance. As a result, purchasers of our common stock may be unable at any given time to sell their shares at or above the price they paid for them.
Any of these events, as well as other circumstances discussed in these Risk Factors, may cause the price of our common stock to fluctuate. In addition, the stock market in general, and the market prices of publicly-traded technology companies in particular, have experienced significant volatility that often has been unrelated to the operating performance of affected companies. These broad stock market fluctuations may adversely affect the market price of our common stock, regardless of our operating performance.
Changes in accounting principles and guidance, or their interpretation or implementation, may materially adversely affect our reported results of operations or financial position. We prepare our consolidated financial statements in accordance with accounting principles generally accepted in the United States of America ("GAAP"). These principles are subject to interpretation by the SEC and various bodies formed to create and interpret appropriate accounting principles and guidance. A change in these principles or guidance, or in their interpretations, may have a significant effect on our reported results, as well as our processes and related controls.
Management's Discussion & Analysis (MD&A)
Removed heading “Revenue by Region”
Removed heading “Income from Operations”
Largest changes
As previously disclosed, followingsee in full comparison(i) the detection of irregular activity on certain portions of our corporate network that was disclosed on December 19, 2022 ("November 2022 Cyber Incident"), and (ii)the discovery of the MOVEit Vulnerability that was disclosed on June 5, 2023, in each instance, we engaged outside cybersecurity experts and other incident response professionals to conduct a forensic investigation and assess the extent and scope of these matters. Cyber incident and MOVEit Vulnerability costs relate to the engagement of external cybersecurity experts and other incident response professionals and are net of received and expected insurance recoveries.We did not incur costs related to the November 2022 cyber incident during fiscal year 2024 and do not expect to incur additional costs as the investigation is closed.See Note19:17, Cyber RelatedMattersMatters, in Part II, Item 8 of this Form 10-K for further discussion.
As more fully discussed in Notesee in full comparison19:17, Cyber RelatedMattersMatters,tointhePartconsolidatedII,financialItemstatements,8 of this Form 10-K, in May 2023, the Company discovereda zero-day vulnerability in its MOVEit Transfer and MOVEit Cloud software product offerings ("the MOVEitVulnerability"),Vulnerability, which resulted in government inquiries and investigations,andasprivatewelllitigation thatas theJudicial Panel on Multidistrict Litigation transferred to the District of Massachusetts for coordinated and consolidated proceedings (the "MDL"),MDL, which may result in adverse judgments, settlements, fines, penalties, or other resolutions, the amount, scope and timing of which could be material, but which the Company is currently unable to predict.
Total other expense, net,see in full comparisondecreasedincreased in fiscal year20242025 due to increases in interestincome and other, net,expense resulting fromhigher interest rates on our invested cash balance. Interest expense increased due tocosts associated with drawing on our revolving line of credit to acquireShareFile, offset by lower interest rates as a result of our debt refinancing in the second quarter of fiscal year 2024, in which we issued the 2030 Notes and entered into an amended and restated credit facility.ShareFile. Refer to Note8:6, Debt, in Part II, Item 8 of this Form 10-K for further discussion. Foreign currencylossloss,decreasednetyearincreasedover yearyear-over-year due to rate volatility and timing of intercompany and hedge settlement activities. Interest income and other, net decreased in fiscal year 2025 due to decreases in interest income on our invested cash balances.
Restructuring expenses recorded in fiscal yearsee in full comparison20242025 primarily relate to headcount reductions in connection with the restructuring action related to the ShareFile acquisition in November 2024 and to afacilityheadcountclosurereduction action inconnectionNovemberwith the restructuring action related to the MarkLogic acquisition.2025. See Note15:13,Restructuring to our Consolidated Financial StatementsRestructuring, in Part II, Item 8 of this Form 10-K for additional details, including types of expenses incurred and the timing of future expenses and cash payments.
Full comparison: every changed paragraph (61)
The following Management’sManagement's Discussion and Analysis of Financial Condition and Results of Operations ("MD&A") is intended to help the reader understand the results of operations and financial condition of Progress Software Corporation. MD&A is provided as a supplement to, and should be read in conjunction with, our consolidated financial statements and the accompanying Notes to Financial Statements (in Part II, Item 8 of this Form 10-K).10-K. This section generally discusses the results of our operations for the year ended November 30, 20242025 compared to the year ended November 30, 2023.2024. For a discussion of the year ended November 30, 20232024 compared to the year ended November 30, 2022,2023, please refer to Part II, Item 7, "Management’sManagement's Discussion and Analysis of Financial Condition and Results of Operations" in our Annual Report on Form 10-K for the year ended November 30, 2023.2024.
As exchange rates are an important factor in understanding period to period comparisons, we believe the presentation of revenue growth rates on a constant currency basis enhances the understanding of our revenue results and evaluation of our performance in comparison to prior periods. The constant currency information presented is calculated by translating current period results using prior period weighted average foreign currency exchange rates. These results should be considered in addition to, not as a substitute for, results reported in accordance with GAAP.accounting principles generally accepted in the United States of America ("GAAP").
We are pursuing a total growth strategy driven by accretive acquisitions of businesses and products that meet our strict strategic, financial, and operating criteria, which help to further our goal of providing stockholder returns. In April 2019, we acquired Ipswitch; in October 2020, we acquired Chef Software; in November 2021, we acquired Kemp Technologies; in February 2023, we acquired MarkLogic; and in October 2024, we acquired ShareFile.ShareFile; and in June 2025, we acquired Nuclia.
We expect to continue to pursue acquisitions meeting our financial criteria that are designed to expand our business and drive significant stockholder returns. As a result, our expected uses of cash could change, our cash position could be reduced, and we may incur additional debt obligations to the extent we complete additional acquisitions. However, we currently believe that existing cash balances, together with funds generated from operations and amounts available under our Credit Facility, will be sufficient to finance our operations and meet our foreseeable cash requirements, including stock repurchases to Progress stockholders,repurchases, through at least the next twelve months.
On October 31, 2024, we acquired certain assets and liabilities that comprise the ShareFile Business ("ShareFile") from Cloud Software Group, Inc. and its subsidiaries ("Cloud") for an aggregate purchase price of $875.0 million in cash, subject to a $25.0 million working capital credit and certain customary adjustments. The transaction was funded through $730.0 million in borrowings under our existing $900.0 million revolving credit facility and cash on hand, resulting in a payment at closing of $852.7 million. As a result of this acquisition, we recorded $96.2 million of deferred revenue and $465.0$464.0 million of intangible assets, as further described in Note 7:5, Business Combinations.Combinations, Thein CompanyPart expectsII, Item 8 of this Form 10-K. During fiscal 2025, the revenue from ShareFile was $261.6 million. We expect to recognize additional servicesSoftware-as-a-Service ("SaaS") revenue, as well as increased amortization expense and interest expense, in future periods as a result of this acquisition.
Total revenue increased as compared to the same period last year primarily due to our acquisition of ShareFile in the fourth quarter of fiscal year 2024. ShareFile revenue in fiscal year 2025 was $261.6 million. With an acquisition date of November 2024, ShareFile only contributed one month of revenue in fiscal year 2024 totaling $21.1 million.
The increase in revenue in fiscal year 2024 was driven by the acquisitions of MarkLogic and ShareFile, and growth in sales of our OpenEdge product offerings. MarkLogic was acquired in February 2023 and as a result, only contributed approximately ten months to our fiscal year 2023 results. ShareFile was acquired in November 2024 and its one-month contribution to our fiscal year 2024 results is $21.1 million.
Software LicenseLicenses Revenue
Software licenselicenses revenue increaseddecreased inby fiscal$11.4 million as compared to the same period last year 2024 primarily due to the acquisitiontiming of MarkLogic,multi-year assubscription well as increasesrenewals in licenseour salesDataDirect inproduct OpenEdge.offering.
MaintenanceMaintenance, SaaS, and Professional Services Revenue
Maintenance revenue remained relatively flat as compared to the same period last year. SaaS revenue increased as compared to the same period last year due to our acquisition of ShareFile. Professional services revenue decreased compared to the same period last year primarily due to a decrease in MarkLogic professional services revenue.
Maintenance revenue increased in fiscal year 2024 primarily due to the acquisition of MarkLogic, as well as an increase in maintenance revenue from our OpenEdge product offerings. The increase in maintenance revenue was partially offset by a decrease in Kemp LoadMaster and Chef maintenance revenue. Services revenue increased primarily due to our acquisition of ShareFile.
Revenue by Region
Total revenue generated in North America increased $35.3 million, and total revenue generated outside North America increased $23.6 million, in fiscal year 2024. The increases in North America and EMEA were primarily due to the acquisitions of MarkLogic and ShareFile, as well as growth in sales of our OpenEdge product offerings. Revenue from Latin America decreased slightly due to the negative impact of foreign exchange. Revenue from Asia Pacific increased due to contributions from multiple products.
Total revenue generated in markets outside North America represented 41% of total revenue in fiscal year 2024 and fiscal year 2023.
Cost of software licenses consists primarily of royalties, electronic software distribution, duplication, and packaging. Cost of software licenses as a percentage of software licenselicenses revenue varies from period to period depending upon the relative product mix. The increase as compared to the same period last year was primarily due to increased hardware sales.
Cost of MaintenanceMaintenance, SaaS, and Professional Services
Cost of maintenancemaintenance, SaaS, and professional services consists primarily of costs of hosting, personnel costs for providing customer support, consulting, and education. The increase year-over-year was primarily due to increased headcount and hosting costs resulting from our acquisitionsacquisition of MarkLogic and ShareFile, partially offset by decreased contractors and outside services costs.
Amortization of Acquired Intangibles - Costs of Revenue
Amortization of acquired intangibles included in costs of revenue primarily represents the amortization of the value assigned to technology-related intangible assets obtained in business combinations. The yearyear-over-year over year decreaseincrease was due to certain intangible assets becoming fully amortized in the second quarteracquisitions of fiscal year 2024, partially offset by the addition of MarkLogicShareFile and ShareFile acquired intangibles.Nuclia.
Gross Profit
Our gross profit increased primarily due to the increase in revenue, partially offset by the increase in costs of maintenance and services.
Sales and marketing expenses increased in fiscal year 20242025 due to increased personnel related,related marketing,costs, increased marketing and sales events costs associated with our acquisitions of MarkLogiccosts, and ShareFile, partially offset by decreases inincreased contractors and outside services costs.costs, each associated with our acquisition of ShareFile.
Product development expenses increased in fiscal year 20242025 primarily due to increased personnel related costs associated with our acquisitions of MarkLogic and ShareFile,costs, as well as an increase in contractors and outside services costs.costs, each associated with our acquisition of ShareFile.
General and administrative expenses include the costs of our finance, human resources, legal, information systemssystems, and administrative departments. General and administrative expenses increased in fiscal year 20242025 primarily due to higher personnel related costscosts, contractors and outside services, and other general and administrative costs, each associated with our acquisitionsacquisition of MarkLogic and ShareFile, partially offset by a decrease in contractors and outside services costs.ShareFile.
Amortization of Acquired Intangibles - Operating Expenses
Amortization of intangibles included in operating expenses primarily represents the amortization of value assigned to intangible assets obtained in business combinations other than assets identified as purchased technology. The yearyear-over-year over year decreaseincrease was due to certain intangible assets becoming fully amortized in the second quarteracquisitions of fiscal year 2024, partially offset by the addition of MarkLogicShareFile and ShareFile acquired intangibles.Nuclia.
Restructuring expenses recorded in fiscal year 20242025 primarily relate to headcount reductions in connection with the restructuring action related to the ShareFile acquisition in November 2024 and to a facilityheadcount closurereduction action in connectionNovember with the restructuring action related to the MarkLogic acquisition.2025. See Note 15:13, Restructuring to our Consolidated Financial StatementsRestructuring, in Part II, Item 8 of this Form 10-K for additional details, including types of expenses incurred and the timing of future expenses and cash payments.
Acquisition-related costs are expensed as incurred and include those costs incurred as a result of a business combination. These costs primarily consist of professional services fees, including third-party legal and valuation-related fees, as well as retention fees. Acquisition-related expenses in fiscal year 20242025 were primarily related to the acquisitionacquisitions of ShareFile,ShareFile and Nuclia, as well as our pursuit of other acquisition opportunities. Acquisition-related expenses in fiscal year 20232024 were primarily related to our acquisition of MarkLogic.ShareFile, as well as our pursuit of other acquisition opportunities.
As previously disclosed, following (i) the detection of irregular activity on certain portions of our corporate network that was disclosed on December 19, 2022 ("November 2022 Cyber Incident"), and (ii) the discovery of the MOVEit Vulnerability that was disclosed on June 5, 2023, in each instance, we engaged outside cybersecurity experts and other incident response professionals to conduct a forensic investigation and assess the extent and scope of these matters. Cyber incident and MOVEit Vulnerability costs relate to the engagement of external cybersecurity experts and other incident response professionals and are net of received and expected insurance recoveries. We did not incur costs related to the November 2022 cyber incident during fiscal year 2024 and do not expect to incur additional costs as the investigation is closed. See Note 19:17, Cyber Related MattersMatters, in Part II, Item 8 of this Form 10-K for further discussion.
Income from Operations
Income from operations increased year over year due to an increase in revenue, offset by an increase in costs of revenue and operating expenses, as shown above.
Total other expense, net, decreasedincreased in fiscal year 20242025 due to increases in interest income and other, net,expense resulting from higher interest rates on our invested cash balance. Interest expense increased due to costs associated with drawing on our revolving line of credit to acquire ShareFile, offset by lower interest rates as a result of our debt refinancing in the second quarter of fiscal year 2024, in which we issued the 2030 Notes and entered into an amended and restated credit facility.ShareFile. Refer to Note 8:6, Debt, in Part II, Item 8 of this Form 10-K for further discussion. Foreign currency lossloss, decreasednet yearincreased over yearyear-over-year due to rate volatility and timing of intercompany and hedge settlement activities. Interest income and other, net decreased in fiscal year 2025 due to decreases in interest income on our invested cash balances.
Our effective income tax rate was 27%10% and 12%27% for fiscal years 20242025 and 2023,2024, respectively. The primary reason for the increaseyear-over-year decrease in the effective rate was due to the increase in tax expense recorded associated with the change in the Company’s indefinite reinvestment assertion during 2024. As a result of the ShareFile acquisition,because the Company has determined that a substantial portion of unremitted foreign earnings are no longer indefinitely reinvested. The Company recorded atax liabilityexpense of $13.7 million in fiscal year 2024 related to the taxes expected to be imposed upon the repatriation of unremitted foreign earnings that arewere not considered indefinitely reinvested. In fiscal year 2025, the Company recorded a tax benefit of $7.5 million as a result of a change in the Company’s estimate of its deferred tax liability associated with unremitted foreign earnings.
On July 4, 2025, the One Big Beautiful Bill Act ("OBBBA") was enacted into law, introducing significant changes to the U.S. federal income tax system. The legislation contains key modifications to the provisions of the 2017 Tax Cuts and Jobs Act and has multiple effective dates. There is no material impact to the tax provision for fiscal 2025. The majority of the legislative provisions become effective in our fiscal years 2026 and 2027. The enactment of OBBBA is not expected to materially impact our fiscal year 2026 provision for income taxes; however, we do expect a reduction in current taxes payable as a result of OBBBA because beginning in our fiscal 2026, provisions under OBBBA allow for an immediate deduction for U.S. R&E expenditures. We will continue to evaluate the full impact of these legislative changes as additional guidance becomes available.
Net Income
We disclose ARR as a performance metric to help investors better understand and assess the performance of our business because our mix of revenue generated from recurring sources currently represents the substantial majority of our revenues and is expected to continue in the future. We define ARR as the annualized revenue of all active and contractually binding term-based contracts from all customers at a point in time. ARR includes revenue from maintenance, software upgrade rights, public cloud, and on-premises subscription-based transactions and managed services. ARR mitigates fluctuations in revenue due to seasonality, contract termterm, and the sales mix of subscriptions for term-based licenses and SaaS. ManagementWe usesuse ARR to understand customer trends and the overall health of the Company’sCompany's business, helping it to formulate strategic business decisions.
Our ARR was $842.0$852.0 million and $578.0$837.0 million as of November 30, 20242025 and 2023,2024, respectively, which is an increase of 46%2% year-over-year. The growth in ARR was primarily driven by the acquisition of ShareFile.
We calculate net retention rate as of a period end by starting with the ARR from the cohort of all customers as of 12 months prior to such period end ("Prior Period ARR"). We then calculate the ARR from these same customers as of the current period end ("Current Period ARR"). Current Period ARR includes any expansion and is net of contraction or attrition over the last 12 months but excludes ARR from new customers in the current period. We then divide the total Current Period ARR by the total Prior Period ARR to arrive at the net retention rate. Net retention rate is not calculated in accordance with GAAP.GAAP and is not derived from a GAAP measure.
The decrease in cash and cash equivalents of $8.9$23.3 million from the end of fiscal year 20232024 was primarily due to cash outflows of $852.7 million to acquire ShareFile, $261.3$130.0 million to pay off the balance of the term loan, $110.0 million to pay offdown the revolving line of credit, repurchases of common stock of $86.8$105.0 million, dividend$20.3 paymentsmillion ofto $31.5acquire million,Nuclia, payment of debt issuance costs of $6.8$6.2 million, and purchases of property and equipment of $5.2$5.7 million. These cash outflows were partially offset by cash inflows from operations of $235.2 million, and the effect of exchange rates on cash of $3.2 million. These cash outflows were partially offset by $730 million in proceeds from our revolving line of credit to partially fund the acquisition of ShareFile, the issuance of convertible senior notes of $396.5 million (net of purchases of capped calls in connection with the convertible notes offering of $42.2 million and issuance costs of $11.2 million), cash inflows from operations of $211.5$6.8 million, and $10.6$3.8 million in cash received from the issuance of common stock. We refinanced our debt by issuing the convertible senior notes and used the proceeds to pay off the outstanding balance of the term loan and revolving line of credit under our previous credit agreement. Except as described below, there are no limitations on our ability to access our cash and cash equivalents.
Cash and cash equivalents held by our foreign subsidiaries were $69.2$55.1 million at November 30, 2024.2025. As a result of the ShareFile acquisition, in the fourth quarter of fiscal 2024 we determined that a substantial portion of unremitted foreign earnings are no longer indefinitely reinvested. As a result of this, we plan to utilize worldwide cash based on the needs of the parent entity. These amounts will be repatriated as needed. Deferred taxes are recorded for earnings of our foreign operations that we determine are not indefinitely reinvested. Refer to Note 16:14, Income TaxesTaxes, in Part II, Item 8 of this Form 10-K for further information.
The increase in cash generated from operations in fiscal year 20242025 as compared to fiscal year 20232024 was primarily due to higher billings and collections, lowerpartially taxesoffset paidby as compared to fiscal year 2023, and slightly lowerincreased interest ratesexpense becauseresulting from the draw down on our revolving line of our debt refinancingcredit in the secondfourth quarter of fiscal year 2024.2024, and increased costs of revenue and operating expenses associated with our acquisition of ShareFile.
Our gross accounts receivable as of November 30, 2024,2025, increased by $37.6$37.7 million from the end of fiscal year 2023.2024. Days sales outstanding ("DSO") in accounts receivable increased to 6773 days as compared to 6267 days in fiscal year 20232024 due to the timing of billings and collections. In addition, our net deferred revenue as of November 30, 2024,2025, increased by $109.4$20.7 million from the end of fiscal year 2023, primarily due to the acquisition of ShareFile in November 2024.
Cash Flows (used in) from Investing Activities
Net cash outflows and inflows of our net investment activity are generally a result of the timing of our purchases and maturities of securities, which are classified as cash equivalents, as well as the timing of acquisitions and divestitures.acquisitions. Included in investing activities in fiscal yearsyear 2025 was the acquisition of Nuclia for a net cash paid amount of $20.0 million, as well as $1.2 million of additional ShareFile purchase consideration. In fiscal year 2024 andwe 2023 were the acquisitions ofacquired ShareFile and MarkLogic for a net cash paid amount of $852.7 million and $355.3 million, respectively. In fiscal year 2022 we received $26.0 million net proceeds from the sale of long-lived assets.million.
Cash Flows from (used in) from Financing Activities
During fiscal year 2025 we made payments on our revolving line of credit of $130.0 million and made $6.2 million in payments for issuance costs related to the amendment of the revolving credit facility. During fiscal year 2024 we received $748.5 million in net proceeds from debt related to the refinancing of our debt in the second quarter of fiscal year 2024 and the draw down on our revolving line of credit in the fourth quarter of 2024,2024. eachWe also repurchased $105.0 million of our common stock under our share repurchase plan in fiscal year 2025 as describedcompared above.to We received proceeds from the issuance of debt of $195.0$86.8 million in fiscal year 2023. The debt proceeds were offset by payments on our long-term debt of $91.9 million in fiscal year 2023 (including a $85.0 million repayment on the revolving line of credit).2024. In addition, in fiscal year 2024,2025, we received $27.8$19.0 million from the exercise of stock options and the issuance of shares under our employee stock purchase plan as compared to $26.0$27.8 million in fiscal year 2023. We also repurchased $86.8 million of our common stock under our share repurchase plan in fiscal year 2024, compared to $34.0 million in fiscal year 2023.2024.
In fiscal years 2025, 2024, 2023 and 2022,2023, we repurchased and retired 2.1 million, 1.6 million, 0.6 million and 1.70.6 million shares of our common stock for $105.0 million, $86.8 million, $34.0 million and $77.0$34.0 million, respectively. On JanuarySeptember 10,23, 2023,2025, our Board of Directors increased ourthe share repurchase authorization by $150.0$200.0 million, to an aggregate authorization of $228.0$242.2 million. As of November 30, 2024,2025, there was $107.2$202.2 million remaining under the current share repurchase authorization. The timing and amount of any shares repurchased will be determined by management based on its evaluation of market conditions and other factors, and the Board of Directors may choose to suspend, expand, or discontinue the repurchase program at any time. Excise tax was insignificant for all years presented.
Upon the closing of the ShareFile acquisition on October 31, 2024, our Board of Directors approved the suspension of our quarterly dividends. We plan to redirect such capital toward the repayment of debt to increase liquidity for future M&A and for share repurchases, both of which are prioritized in our capital allocation policy. Prior to the suspension of the quarterly dividend in the fourth fiscal quarter of 2024, we had paid aggregate cash dividends totaling $31.5 million, $31.6 million and $31.1$31.6 million for the years ended November 30, 2024,2024 and 2023, and 2022, respectively.
See Note 6, Debt, in Part II, Item 8 of this Form 10-K for further information.
See Note 8: Debt to the consolidated financial statements.
We include standard intellectual property indemnification provisions in our licensing agreements in the ordinary course of business. Pursuant to our product license agreements, we will indemnify, hold harmless, and agree to reimburse the indemnified party for losses suffered or incurred by the indemnified party, generally business partners or customers, in connection with certain patent, copyrightcopyright, or other intellectual property infringement claims by third parties with respect to our products. Other agreements with our customers provide indemnification for claims relating to property damage or personal injury resulting from the performance of services by us or our subcontractors. Historically, our costs to defend lawsuits or settle claims relating to such indemnity agreements have been insignificant. Accordingly, the estimated fair value of these indemnification provisions is immaterial.insignificant. ForPlease see Note 17, Cyber Related Matters, in Part II, Item 8 of this Form 10-K for further details regarding indemnification claims related to the MOVEit Vulnerability. Please see Note 19: Cyber Related Matters to the consolidated financial statements for further details.
Cash from operations in fiscal year 20252026 could be affected by various risks and uncertainties, including, but not limited to, the effects of various risks detailed in Part I, Item 1A titled "Risk Factors", including increased disruption and volatility in capital markets and credit markets that could adversely affect our liquidity and capital resources in the future. However, based on our current business plan, we believe that existing cash balances, together with funds generated from operations and amounts available under ourthe revolvingCredit credit facility,Facility, will be sufficient to finance our operations and meet our foreseeable cash requirements through at least the next twelve months. Our foreseeable cash needs include capital expenditures, acquisitions, debt repayments, share repurchases, lease commitments, restructuring obligationsobligations, and other long-term obligations.
We expect to continue to make payments on the Credit Facility and are also continuously evaluating additional financing options, the net proceeds of which could be used for general corporate purposes or to repay outstanding indebtedness. In the future, we expect to use the available capacity under the Credit Facility for any payments made in connection with any settlement of the 2026 Notes upon conversion, redemption, or repayment of our 2026 Notes at or prior to the 2026 Notes maturity. We may also use the available capacity for general corporate purposes.
Our contracts with customers typically include promises to license one or more products and services to a customer. Determining whether products and services are distinct performance obligations that should be accounted for separately requires significant judgment. Significant judgment is also required to determine the stand-alone selling price ("SSP") of each distinct performance obligation. Our licenses are sold as perpetual or term licenses, and the arrangements typically contain various combinations of maintenancemaintenance, SaaS, and professional services, which are generally accounted for as separate performance obligations. WeFor generallycertain product offerings, we use the residual approach to allocate the transaction price to our software license performance obligations because, due to the pricing of our licenses being highly variable, they do not have an observable SSP.
MaintenanceRevenue revenuerelated to maintenance and SaaS offerings is recognized ratably over the contract period. The SSP of maintenance services is a percentage of the net selling price of the related software license. The SSP of SaaS performance obligations is determined based upon observable prices in stand-alone SaaS transactions. Professional services revenue is generally recognized as the services are delivered to the customer. The SSP of professional services is based upon observable prices in similar transactions using the hourly rates sold in stand-alone services transactions. ServicesProfessional services are either sold on a time and materials basis or prepaid upfront. Revenue related to software-as-a-service ("SaaS") offerings is recognized ratably over the contract period. The SSP of SaaS performance obligations is determined based upon observable prices in stand-alone SaaS transactions.
As more fully discussed in Note 19:17, Cyber Related MattersMatters, toin thePart consolidatedII, financialItem statements,8 of this Form 10-K, in May 2023, the Company discovered a zero-day vulnerability in its MOVEit Transfer and MOVEit Cloud software product offerings ("the MOVEit Vulnerability"),Vulnerability, which resulted in government inquiries and investigations, andas privatewell litigation thatas the Judicial Panel on Multidistrict Litigation transferred to the District of Massachusetts for coordinated and consolidated proceedings (the "MDL"),MDL, which may result in adverse judgments, settlements, fines, penalties, or other resolutions, the amount, scope and timing of which could be material, but which the Company is currently unable to predict.
There is complexity in applying this accounting framework for the potential losses arising from the MOVEit Vulnerability and in determining whether a loss is probable and estimable as these claims and proceedings are subject to inherent uncertainties and potential damages for which we are unable to arrive at a reasonable estimate. Further, the outcome of these matters may not be known for prolonged periods of time. Since the MDL remains in thea relatively early stages; andstage, alleged damages have not been specified, there is uncertainty as to the likelihood of a class or classes being certified or the ultimate size of any class if certified, and there are significant factual and legal issues to be resolved, we are currently unable to develop an estimate of the losses or range of losses incurred (if any). Therefore, we have not recorded a loss contingency liability for the MOVEit Vulnerability as of November 30, 2024.2025. The Company could incur judgments or enter into settlements regarding the outcome of these claims and proceedings, which could have a material effect on the estimated amount of the liability in the period in which the effect becomes probable and reasonably estimable.
We have incurred expenses related to our efforts to investigate and remediate the MOVEit Vulnerability, as well as legal and other professional services related thereto. Expenses are recognized as they are incurred and are recognized net of expected insurance recoveries, although the timing of recognizing insurance recoveries may differ from the timing of recognizing the associated expenses. We incurred expenses of $2.8 million, $5.6 millionmillion, and $1.5 million, net, related to the MOVEit Vulnerability for the fiscal years ended November 30, 20242025, 2024, and 2023, respectively.
During the period when the MOVEit Vulnerability occurred, we maintained $15.0 million of cybersecurity insurance coverage, which is expected to reduce our exposure to expenses and liabilities arising from these events. As of November 30, 2024,2025, we have recorded approximately $5.8 million in insurance recoveries, and we have $6.7$4.5 million of additionalremaining cybersecurity insurance coverage (whichunder isthe subjectapplicable to a $0.5 million retention per claim).policy. We will pursue recoveries to the maximum extent available under our insurance policies.
What changed in the latest 10-Q
Risk Factors
We operate in a rapidly changing environment that involves certain risks and uncertainties, some of which are beyond our control. In addition to the information provided in this report, please refer to Part I, Item 1A. Risk Factors in our 2025 Annual Report for a more complete discussion regarding certain factors that could materially affect our business, financial condition, or future results.
No wording changes found in this section.
Full comparison: every changed paragraph (0)
Management's Discussion & Analysis (MD&A)
Largest changes
We made payments on our revolving line of credit of $170.0 million through the third quarter of fiscal year 2026 as compared to $110.0 million in the same period of fiscal year 2025. We repurchasedsee in full comparison$55.1$72.0 million of our common stock under our share repurchase plan in the firstsixnine months of fiscal year 2026 as compared to$50.1$65.1 million in the same period of the prior year. Further, we received proceeds from our revolving line of credit of $360.0 million which we used to repurchaseourtheconvertible2026senior noteNotes for $360.0million, and additionally we made payments on our revolving line of credit of $110.0 million through the second quarter of fiscal year 2026 as compared to $70.0 million in the same period of fiscal year 2025.million.
“Sales and marketing expenses decreased in the third quarter of fiscal year 2026 primarily due to decreased variable compensation expenses during the period. Sales and marketing expenses increased in the first nine months of fiscal year 2026 primarily due to increased personnel-related costs and higher marketing and sales events costs.”see in full comparison
On September 23, 2025, our Board of Directors increased the share repurchase authorization by $200.0 million to an aggregate authorization of $242.2 million. During the three andsee in full comparisonsixnine months endedMayAugust 31, 2026, we repurchased and retired1.20.5 million shares for$34.7$16.9 million and1.72.2 million shares for$54.7$71.6 million, respectively. During the three andsixnine months endedMayAugust 31, 2025, we repurchased and retired0.40.3 million shares for$20.0$15.0 million and0.91.2 million shares for$50.0$65.1 million, respectively. The shares were repurchased in both periods as part of the share repurchase program as authorized by our Board of Directors. As ofMayAugust 31, 2026, there was$147.5$130.7 million remaining under the current authorization.
As ofsee in full comparisonMayAugust 31, 2026,$70.0$68.8 million of our cash and cash equivalents was held by our foreign subsidiaries.The Company has determined that a substantial portion of unremitted foreign earnings are no longer indefinitely reinvested. As a result of this, weWe plan to utilize worldwide cash based on the needs of the parententity.entity, including principal payments on our revolving credit facility. These amounts will be repatriated asneeded.needed,Deferredand deferred taxes are recorded for earnings of our foreign operations that we determine are not indefinitely reinvested.
“Product development expenses decreased in the third quarter of fiscal year 2026 primarily due to decreased headcount related costs. In the first nine months of fiscal year 2026 product development expenses increased primarily due to increased personnel-related costs.”see in full comparison
Acquisition-related costs are expensed as incurred and include those costs incurred as a result of business combinations. These costs consist of professional service fees, including third-party legal and valuation-related fees. Thesee in full comparisondecreaseincrease in acquisition-related expenses in thesecondthird quarter ofand first six monthsfiscal year 2026 are due to our acquisition of Domo. The decrease in acquisition costs in the first nine months of fiscal year 2026 was due to the fair value adjustment related to the contingent earn-out to former Nuclia shareholders. See Note 4, BusinessCombinations,Combination.acquisition-relatedAcquisition-related expenses in the sameperiodperiods of fiscal year 2025 were primarily related to ouracquisitionacquisitions ofShareFile.ShareFile and Nuclia.
Full comparison: every changed paragraph (25)
This Quarterly Report on Form 10-Q may contain information that are "forward-looking statements" within the meaning of Section 27A of the Securities Act of 1933, as amended; Section 21E of the Securities Exchange Act of 1934, as amended; and the Private Securities Litigation Reform Act of 1995. Whenever we use words such as "believe," "may," "could," "would," "might," "should," "expect," "intend," "plan," "estimate," "target," "anticipate" and negatives and derivatives of these or similar expressions, or when we make statements concerning future financial results, product offerings, or other events that have not yet occurred, we are making forward-looking statements. Actual future results may differ materially from those contained in or implied by our forward-looking statements due to various factors which are more fully described in Part I, Item 1A. Risk Factors in our 2025 Annual Report as well as any risk factors described in Part II, Item 1A of this Quarterly Report on Form 10-Q. Although we have sought to identify the most significant risks to our business, we cannot predict whether, or to what extent, any of such risks may be realized. We also cannot assure you that we have identified all possible issues that we might face. We undertake no obligation to update any forward-looking statements that we make.
Total revenue increaseddecreased in the secondthird quarter of fiscal year 2026 as compared to the same period last year primarily due to the timing of renewals on multiyear subscription contracts. Total revenue increased in the first nine months of fiscal year 2026 due to increases in license sales as well as a positive impact from foreign currency exchange, while maintenance, SaaS, and professional services were essentially unchanged from prior periods.
Software licenses revenue increasedremained flat in the secondthird quarter of fiscal year 2026 primarily duecompared to increasesthe same period in ourthe DataDirect,prior Chef, and MarkLogic product offerings.year. Software licenses revenue increased in the first sixnine months of fiscal year 2026 primarily due to increases in our DataDirect, MarkLogic,DataDirect and OpenEdge product offerings.
Maintenance and SaaS revenue were essentially unchanged from prior periods. Professionalprofessional services revenue decreased slightly across multiple product offerings as compared to the same periods last year. SaaS revenue slightly increased compared to prior periods presented.
Cost of software licenses consists primarily of royalties, electronic software distribution, duplication, and packaging. Cost of software licenses as a percentage of software license revenue varies from period to period depending upon the relative product mix. The increasesincrease in the second quarter and first sixnine months of fiscal year 2026 compared to the same periodsperiod last year werewas relateddue to increased royalty costs.
Cost of maintenance, SaaS, and professional services consist primarily of hosting costs,costs and personnel-related costs attributable to customer support, cloud operations, consulting, and education. The decreases in all periods shown are primarily due to decreased contractors and headcount relatedpersonnel-related costs in fiscal year 2026.
Sales and marketing expenses decreased in the third quarter of fiscal year 2026 primarily due to decreased variable compensation expenses during the period. Sales and marketing expenses increased in the first nine months of fiscal year 2026 primarily due to increased personnel-related costs and higher marketing and sales events costs.
Sales and marketing expenses increased in all periods presented due to increased personnel-related costs, partially offset by lower marketing and sales events costs. These costs as a percentage of total revenue were 21% in all periods presented.
Product development expenses decreased in the third quarter of fiscal year 2026 primarily due to decreased headcount related costs. In the first nine months of fiscal year 2026 product development expenses increased primarily due to increased personnel-related costs.
Product development expenses increased in all periods presented primarily due to increased personnel-related costs.
General and administrative expenses include the costs of our finance, human resources, legal, information systems, and administrative departments. The increasesdecrease in allthe periodsthird shownquarter of fiscal year 2026 was due to lower personnel-related costs. The increase in the first nine months of fiscal year 2026 was due to higher stock-based compensation expense and additional reserves related to our receivables, partially offset by lower contractors and outside services costs.
Since the discovery of the MOVEit Vulnerability that was disclosed on June 5, 2023, we have incurred expenses and will incur future costs related to the MOVEit Vulnerability.thereto. Such costs and expenses are net of received insurance recoveries. As of August 31, 2026, there is no remaining insurance recovery available to reduce costs incurred related to the MOVEit Vulnerability. Please refer to Note 12, Cyber Related Matters for additional details,details and updates regarding the MOVEit Vulnerability.
Restructuring expenses recorded in the secondthird quarter and first sixnine months of fiscal year 2026 primarily relate to the headcount reduction action in November 2025, and facility closures in other existing restructuring actions. Restructuring expenses recorded in the secondthird quarter and first sixnine months of fiscal year 2025 primarily relate to headcount reductions and a facility closure in connection with the restructuring action related to the ShareFile acquisition in November 2024. See Note 9, Restructuring for additional details, including types of expenses incurred and the timing of future expenses and cash payments.
Acquisition-related costs are expensed as incurred and include those costs incurred as a result of business combinations. These costs consist of professional service fees, including third-party legal and valuation-related fees. The decreaseincrease in acquisition-related expenses in the secondthird quarter of and first six months fiscal year 2026 are due to our acquisition of Domo. The decrease in acquisition costs in the first nine months of fiscal year 2026 was due to the fair value adjustment related to the contingent earn-out to former Nuclia shareholders. See Note 4, Business Combinations,Combination. acquisition-relatedAcquisition-related expenses in the same periodperiods of fiscal year 2025 were primarily related to our acquisitionacquisitions of ShareFile.ShareFile and Nuclia.
Total other expense, net, decreased in the secondthird quarter and first sixnine months of fiscal year 2026 due to a lower weighted average balance and interest rate on our revolving line of credit as compared to the same periods last year. These decreases in interest expense were partially offset by the redemption of our 2026 Notes in April, which was funded by drawing on our revolving line of credit that carries a higher interest rate than the Notes. Refer to Note 5, Debt for further discussion. Foreign currency loss decreased year-over-year due to rate volatility and timing of intercompany and hedge settlement activities.
Our effective tax rate was 27%23% and 14%26% in the secondthird fiscal quarters of 2026 and 2025, respectively. The increasedecrease in the effective rate is primarily due to changes in the jurisdictional mix of earnings, including the proportion of U.S. versus non-U.S. income, and minimal discrete tax expense of $0.8 millionbenefit in the secondthird fiscal quarter of 2026 compared to a discrete tax benefitexpense of $1.1$2.0 million in the secondthird fiscal quarter of 2025.
Our ARR was $868$873 million and $850$861 million as of MayAugust 31, 2026 and 2025, respectively, which is an increase of 2%1% year-over-year.
As of MayAugust 31, 2026, $70.0$68.8 million of our cash and cash equivalents was held by our foreign subsidiaries. The Company has determined that a substantial portion of unremitted foreign earnings are no longer indefinitely reinvested. As a result of this, weWe plan to utilize worldwide cash based on the needs of the parent entity.entity, including principal payments on our revolving credit facility. These amounts will be repatriated as needed.needed, Deferredand deferred taxes are recorded for earnings of our foreign operations that we determine are not indefinitely reinvested.
The increase in cash generated from operations in the first sixnine months of fiscal year 2026, as compared to the same period last year, was primarily attributable to higher collections, increased income from operations, and lower interest expense.
Our gross accounts receivable as of MayAugust 31, 2026, decreased by $72.0$78.8 million from the end of fiscal year 2025. Our days sales outstanding ("DSO") in accounts receivable was 4942 days in the secondthird quarter of fiscal year 2026 compared to 5355 days and 73 days in the secondthird and fourth fiscal quarters of 2025, respectively, due to the timing of billings and collections.
Net cash outflows and inflows of our net investment activity are generally a result of capital expenditures as well as the timing of acquisitions. In the first sixnine months of fiscal year 2026, we purchased $4.6$6.3 million of property and equipment. In the secondthird quarter of fiscal year 2025 we had $1.8$2.8 million of purchases of property and equipment and a payment of $1.2$20.7 million related to the acquisition of ShareFile.Nuclia.
We made payments on our revolving line of credit of $170.0 million through the third quarter of fiscal year 2026 as compared to $110.0 million in the same period of fiscal year 2025. We repurchased $55.1$72.0 million of our common stock under our share repurchase plan in the first sixnine months of fiscal year 2026 as compared to $50.1$65.1 million in the same period of the prior year. Further, we received proceeds from our revolving line of credit of $360.0 million which we used to repurchase ourthe convertible2026 senior noteNotes for $360.0 million, and additionally we made payments on our revolving line of credit of $110.0 million through the second quarter of fiscal year 2026 as compared to $70.0 million in the same period of fiscal year 2025.million.
On September 23, 2025, our Board of Directors increased the share repurchase authorization by $200.0 million to an aggregate authorization of $242.2 million. During the three and sixnine months ended MayAugust 31, 2026, we repurchased and retired 1.20.5 million shares for $34.7$16.9 million and 1.72.2 million shares for $54.7$71.6 million, respectively. During the three and sixnine months ended MayAugust 31, 2025, we repurchased and retired 0.40.3 million shares for $20.0$15.0 million and 0.91.2 million shares for $50.0$65.1 million, respectively. The shares were repurchased in both periods as part of the share repurchase program as authorized by our Board of Directors. As of MayAugust 31, 2026, there was $147.5$130.7 million remaining under the current authorization.
Cash from operations in fiscal year 2026 could be affected by various risks and uncertainties, including, but not limited to, the effects of various risks detailed in Part I, Item 1A. Risk Factors in our 2025 Annual Report, including increased disruption and volatility in capital markets and credit markets that could adversely affect our liquidity and capital resources in the future. However, based on our current business plan, we believe that existing cash balances, together with funds generated from operations and amounts available under our revolving credit facility, will be sufficient to finance our operations and meet our foreseeable cash requirements through at least the next twelve months. Our foreseeable cash needs include capital expenditures, acquisitions,acquisitions (including the acquisition of Domo for approximately $400 million, funded with borrowings under our existing revolving credit facility), debt repayments, share repurchases, lease commitments, restructuring obligations, and other long-term obligations.
As previously disclosed, on the evening of May 28, 2023, we learned that our MOVEit Transfer (the on-premise version) and MOVEit Cloud (a cloud-hosted version of MOVEit Transfer) products were attacked by a threat actor who compromised and exfiltrated personal data from various customer-controlled MOVEit Transfer environments. As a result of the MOVEit Vulnerability, we are party to certain class action lawsuits filed by individuals who claim to have been impacted by the exfiltration of data from the environments of our MOVEit Transfer customers, which have been centralized in the MDL. The MDL has also consolidated an insurance subrogation complaint (where an insurer is seeking recovery for expenses incurred on behalf of its insured in connection with the MOVEit Vulnerability) and, as of the date of this filing, one customer cross-claim. Motions to dismiss were filed and partially granted in July 2025, then further partially granted in January 2026 in response to our motions for reconsideration. In all, the court has dismissed, in whole or in part, 23 of the 33 claims asserted by the bellwether plaintiffs in the MDL. The court has ordered the conclusion of fact discovery by September 29, 2026,2026. and that theThe filing of class certification briefing will beginoccurred on August 28, 2026, and will continue into the fourth quarter of 2026. The MDL is not expected to conclude within the next twelve months. As previously disclosed, we have also cooperated with inquiries and investigations from various governmental authorities, a number of which have been formally closed and, as of the date of this filing, have not resulted in any prosecution or enforcement actions.
PRGS insider buying and selling (Form 4)
Since 2026-04-11, insiders reported open-market purchases in 0 Form 4 filings and open-market sales in 6 filings (4 insiders, 6 trade dates, 35,082 shares, about $1.3M; 6 of these filings say the sales were made under a Rule 10b5-1 trading plan). Net open-market shares: -35,082 (purchases minus sales); net value about -$1.3M.Totals add up every open-market (code P and S) line in those filings, using the prices reported in the filings. Awards, option exercises, tax withholding and gifts are listed below but not counted.
| Trade date | Insider | Transaction | Shares | Price | Value |
|---|---|---|---|---|---|
| 2026-10-05 | Wang Yufan Stephanie |
Open-market sale |
1,245 | $37.00 | $46.1K |
| 2026-10-01 | Wang Yufan Stephanie |
Option exercise | 1,038 | — | — |
| 2026-10-01 | Wang Yufan Stephanie |
Shares withheld for tax | 461 | $38.99 | $18.0K |
| 2026-10-01 | Wang Yufan Stephanie |
Option exercise | 1,201 | — | — |
| 2026-10-01 | Wang Yufan Stephanie |
Shares withheld for tax | 533 | $38.99 | $20.8K |
| 2026-10-01 | Wang Yufan Stephanie |
Option exercise | 1,696 | — | — |
| 2026-10-01 | Wang Yufan Stephanie |
Shares withheld for tax | 753 | $38.99 | $29.4K |
| 2026-10-01 | Subramanian Sundar |
Option exercise | 1,168 | — | — |
| 2026-10-01 | Subramanian Sundar |
Shares withheld for tax | 519 | $38.99 | $20.2K |
| 2026-10-01 | Subramanian Sundar |
Option exercise | 1,709 | — | — |
| 2026-10-01 | Subramanian Sundar |
Shares withheld for tax | 758 | $38.99 | $29.6K |
| 2026-10-01 | Subramanian Sundar |
Option exercise | 2,222 | — | — |
| 2026-10-01 | Subramanian Sundar |
Shares withheld for tax | 986 | $38.99 | $38.4K |
| 2026-10-01 | Lococo Domenic |
Option exercise | 807 | — | — |
| 2026-10-01 | Lococo Domenic |
Shares withheld for tax | 237 | $38.99 | $9.2K |
| 2026-10-01 | Lococo Domenic |
Option exercise | 924 | — | — |
| 2026-10-01 | Lococo Domenic |
Shares withheld for tax | 272 | $38.99 | $10.6K |
| 2026-10-01 | Lococo Domenic |
Option exercise | 1,169 | — | — |
| 2026-10-01 | Lococo Domenic |
Shares withheld for tax | 344 | $38.99 | $13.4K |
| 2026-10-01 | Jarrett Loren |
Option exercise | 1,168 | — | — |
| 2026-10-01 | Jarrett Loren |
Shares withheld for tax | 565 | $38.99 | $22.0K |
| 2026-10-01 | Jarrett Loren |
Option exercise | 1,709 | — | — |
| 2026-10-01 | Jarrett Loren |
Shares withheld for tax | 827 | $38.99 | $32.2K |
| 2026-10-01 | Jarrett Loren |
Option exercise | 2,222 | — | — |
| 2026-10-01 | Jarrett Loren |
Shares withheld for tax | 1,075 | $38.99 | $41.9K |
| 2026-10-01 | Gupta Yogesh K |
Option exercise | 7,349 | — | — |
| 2026-10-01 | Gupta Yogesh K |
Shares withheld for tax | 3,554 | $38.99 | $138.6K |
| 2026-10-01 | Gupta Yogesh K |
Option exercise | 8,315 | — | — |
| 2026-10-01 | Gupta Yogesh K |
Shares withheld for tax | 4,021 | $38.99 | $156.8K |
| 2026-10-01 | Gupta Yogesh K |
Option exercise | 11,579 | — | — |
| 2026-10-01 | Gupta Yogesh K |
Shares withheld for tax | 5,599 | $38.99 | $218.3K |
| 2026-10-01 | Folger Anthony |
Option exercise | 2,464 | — | — |
| 2026-10-01 | Folger Anthony |
Shares withheld for tax | 1,093 | $38.99 | $42.6K |
| 2026-10-01 | Folger Anthony |
Option exercise | 3,049 | — | — |
| 2026-10-01 | Folger Anthony |
Shares withheld for tax | 1,353 | $38.99 | $52.8K |
| 2026-10-01 | Folger Anthony |
Option exercise | 4,678 | — | — |
| 2026-10-01 | Folger Anthony |
Shares withheld for tax | 2,075 | $38.99 | $80.9K |
| 2026-10-01 | Ainsworth John |
Option exercise | 1,168 | — | — |
| 2026-10-01 | Ainsworth John |
Shares withheld for tax | 519 | $38.99 | $20.2K |
| 2026-10-01 | Ainsworth John |
Option exercise | 1,709 | — | — |
| 2026-10-01 | Ainsworth John |
Shares withheld for tax | 758 | $38.99 | $29.6K |
| 2026-10-01 | Ainsworth John |
Option exercise | 2,222 | — | — |
| 2026-10-01 | Ainsworth John |
Shares withheld for tax | 986 | $38.99 | $38.4K |
| 2026-08-14 | Folger Anthony |
Open-market sale |
2,000 | $44.80 | $89.6K |
| 2026-07-29 | Jarrett Loren |
Open-market sale |
9,963 | $41.63 | $414.8K |
| 2026-07-29 | Jarrett Loren |
Open-market sale |
1,784 | $41.49 | $74.0K |
| 2026-07-02 | Vitale Vivian M |
Grant/award | 5,857 | $38.42 | $225.0K |
| 2026-07-02 | Tucci Angela |
Grant/award | 5,857 | $38.42 | $225.0K |
| 2026-07-02 | Kane Charles Francis |
Grant/award | 5,857 | $38.42 | $225.0K |
| 2026-07-02 | Krall David |
Grant/award | 5,857 | $38.42 | $225.0K |
| 2026-07-02 | King Samskriti |
Grant/award | 5,857 | $38.42 | $225.0K |
| 2026-07-02 | Gawlick Rainer |
Grant/award | 5,857 | $38.42 | $225.0K |
| 2026-07-02 | Egan John R |
Grant/award | 5,857 | $38.42 | $225.0K |
| 2026-07-02 | Dacier Paul T |
Grant/award | 5,857 | $38.42 | $225.0K |
| 2026-07-01 | Subramanian Sundar |
Option exercise |
10,597 | $38.06 | $403.3K |
| 2026-07-01 | Subramanian Sundar |
Open-market sale |
10,597 | $38.27 | $405.5K |
| 2026-05-19 | Folger Anthony |
Open-market sale |
4,074 | $29.05 | $118.3K |
| 2026-05-19 | Folger Anthony |
Open-market sale |
400 | $29.96 | $12.0K |
| 2026-05-18 | Wang Yufan Stephanie |
Open-market sale |
1,500 | $28.44 | $42.7K |
| 2026-05-18 | Wang Yufan Stephanie |
Open-market sale |
3,519 | $29.04 | $102.2K |
Well-known investors holding PRGS (13F)
| Investor | Quarter | Shares | Reported value | % of their 13F | Change vs prior quarter |
|---|---|---|---|---|---|
| Millennium Management (Israel Englander) | 2026-06-30 | 0 | $54.2M | — | Sold out |
| Oaktree Capital Management (Howard Marks) | 2026-06-30 | 0 | $36.1M | — | Sold out |
| AQR Capital Management (Cliff Asness) | 2026-06-30 | 1,042,345 | $35.0M | 0.01% | Added 167% |
| Point72 Asset Management (Steve Cohen) | 2026-06-30 | 113,291 | $3.8M | 0.01% | Reduced 65% |
| Gotham Asset Management (Joel Greenblatt) | 2026-06-30 | 31,546 | $1.1M | 0.0% | Reduced 4% |
| Two Sigma Investments | 2026-06-30 | 10,369 | $348.2K | 0.0% | Reduced 90% |
| Citadel Advisors (Ken Griffin) | 2026-06-30 | 6,685 | $224.5K | 0.0% | Reduced 87% |