{"url_path":"/sec/aka/10-q/2026/item-1a","section_key":"item-1a","section_title":"Item 1A RISK FACTORS","topic":"sec","document":{"doc_type":"10-Q","doc_date":"2026-05-12","source_url":"https://www.sec.gov/Archives/edgar/data/1865107/0001865107-26-000028-index.html","accession_number":"0001865107-26-000028","cik":"0001865107","ticker":"AKA","issuer_name":"A.K.A. BRANDS HOLDING CORP.","edgar_url":"https://www.sec.gov/Archives/edgar/data/1865107/0001865107-26-000028-index.html","primary_entity_key":"0001865107","primary_entity_name":"A.K.A. BRANDS HOLDING CORP."},"word_count":842,"has_tables":true,"body_markdown":"ITEM 1A. RISK FACTORS\n\nReference is made to the information disclosed under Part I, Item 1A - \"Risk Factors\" in our 2025 Form 10-K, which contains a detailed discussion of certain risk factors that could materially adversely affect the Company's business, operating results or financial condition. The information disclosed under Part I, Item 1A - “Risk Factors” in our 2025 Form 10-K remains current in all material respects, with the exception below.\n\nA security breach or other disruption to our information technology systems could result in the loss, theft, misuse, unauthorized disclosure or unauthorized access of customer, supplier, or sensitive company information or could disrupt our operations, which could damage our relationships with customers, suppliers or employees, expose us to litigation or regulatory proceedings or harm our reputation, any of which could materially adversely affect our business, financial condition or results of operations.\n\nOur business involves the storage and transmission of a significant amount of personal, confidential, or sensitive information, including the personal information of our customers, credit card information, the personal information of our employees, information relating to customer preferences and our proprietary financial, operational and strategic information. The protection of this information is vitally important to us as the loss, theft, misuse, unauthorized disclosure or unauthorized access of such information could lead to significant reputational or competitive harm, result in litigation involving us or our business partners, expose us to regulatory proceedings and cause us to incur substantial liabilities, fines, penalties or expenses. As a result, we believe our future success and growth depends, in part, on the ability of our key business processes and systems, including our information technology and global communication systems, to prevent the theft, loss, misuse, unauthorized disclosure or unauthorized access of this personal, confidential and sensitive information, and to respond quickly and effectively if data security incidents do occur. As with many businesses, we are subject to numerous data privacy and security risks, which may prevent us from maintaining the privacy of this information, result in the disruption of our business and require us to expend significant resources attempting to secure and protect such information and respond to incidents, any of which could materially adversely affect our business, financial condition or results of operations.\n\nThe frequency, intensity, and sophistication of cyber-attacks, ransom-ware attacks and other data security incidents has significantly increased in recent years. As with many other businesses, we have experienced, and are continually at risk of being subject to, attacks and incidents, although none have had a material adverse impact on our financial condition or results of operations. However, as cyberattacks become increasingly sophisticated, including through the use of artificial intelligence (“AI”) technologies, such as deepfakes and AI-generated social engineering, the risk of security incidents has increased. Due to the increased risk of these types of attacks and incidents, we expend significant resources on information technology and data security tools, measures and processes designed to protect our information technology systems, as well as the personal, confidential or sensitive information stored on or transmitted through those systems, and to ensure an effective response to any cyber-attack or data security incident. Whether or not these measures are ultimately successful, these expenditures could have an adverse impact on our financial condition and results of operations and divert management’s attention from pursuing our strategic objectives.\n\n37\n\n[Table of Contents](#i1eff1f6cede745319493dbe5c62304e3_7)\n\nIn addition, although we take the security of our information technology systems seriously, there can be no assurance that the security measures we employ will effectively prevent unauthorized persons from obtaining access to our systems and information. Despite the implementation of reasonable security measures by us and our third-party providers, our systems and information are susceptible to physical or electronic break-ins, security breaches from inadvertent or intentional actions of our employees, third-party service providers, contractors, consultants, business partners or other third parties, from cyber-attacks by malicious third parties (including the deployment of harmful malware, ransomware, denial of service attacks, social engineering and other means to affect service reliability and threaten the confidentiality, integrity and availability of information) or other data security incidents. These risks may be exacerbated in the remote work environment. Threat actors are also increasingly leveraging AI technologies to develop new attack vectors, exploit vulnerabilities, obscure their activities, and increase the difficulty of threat attribution. For example, new AI tools are capable of identifying previously undetected vulnerabilities and creating exposures to zero-day attacks, which may significantly diminish the timeframe for us and our third-party providers to detect, respond to and protect our information technology systems. AI and machine learning technologies continue to develop rapidly, and may result in a variety of unforeseen risks. Because the techniques used to obtain unauthorized access to information technology systems are constantly evolving and becoming more sophisticated, they may not be recognized until launched, and can originate from a wide variety of sources, including outside groups such as external service providers, organized crime affiliates, terrorist organizations or hostile foreign governments or agencies, we may be unable to anticipate these techniques or implement adequate preventive measures in response.\n\n38\n\n[Table of Contents](#i1eff1f6cede745319493dbe5c62304e3_7)"}