RCI Hospitality Holdings
Incident posture
Linked entities
- Victim
- RCI Hospitality Holdings
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
RCI Hospitality Holdings disclosed that an insecure direct object reference vulnerability in an IIS web server allowed unauthorized access to personal information of numerous independent contractors, including names, dates of birth, contact details, Social Security numbers and driver’s license numbers. The breach affected roughly forty thousand individuals, and a review of the exposed files was completed before notification letters were sent. The company reported that no customer data or financial systems were accessed, business operations continued unaffected, and the FBI has been informed of the incident. While the attacker remains unidentified, RCI stated that the data has not been publicly disseminated and will cooperate with any ensuing investigation.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On March 19 2026 the unauthorized access to RCI Hospitality Holdings’ systems began, according to an internal investigation that concluded earlier in April. On March 23 the company’s RCI Internet Services subsidiary identified an insecure direct object reference (IDOR) vulnerability in an IIS web server that allowed attackers to alter a parameter in a URL or request and retrieve records without proper authorization checks. The vulnerability was disclosed to the Securities and Exchange Commission in a mid‑April filing, which noted that the exposure involved personal information of “numerous” independent contractors, including names, dates of birth, contact details, Social Security numbers and driver’s license numbers. RCI stated that, to its knowledge, the unauthorized actor had not publicly disseminated the data and that no customer information or financial systems were accessed. The company also reported that its business operations continued unaffected and that it did not anticipate a material impact from the incident.
Following the discovery, RCI initiated a review of the compromised files, which was completed on May 13 2026. Notification letters were subsequently sent to the affected individuals, and the Federal Bureau of Investigation was informed of the breach. RCI indicated its willingness to cooperate with any ensuing FBI investigation. In a June 6 2026 update the company disclosed that the breach affected roughly 40,000 individuals, a figure that had been uncertain in the earlier April disclosure. No known ransomware group has claimed responsibility for the attack, and the identity of the threat actor remains unknown.
The response actions taken by RCI included securing the vulnerable IIS web server, completing the forensic review of the stolen data, issuing breach notifications to all impacted parties, and maintaining communication with law‑enforcement authorities. The company emphasized that its operational functions were not disrupted and that it does not expect the incident to result in significant financial or reputational harm. RCI continues to monitor the situation and to assist the FBI as required.
Sources
Sources available to members: 2 sources.