CSIDB logo
Incident

RCI Hospitality Holdings

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-16 03:26

Linked entities

Victim
RCI Hospitality Holdings
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Mar 2026
Discovered
Mar 2026
Disclosed
Apr 2026
Resolved
Pending

Summary

RCI Hospitality Holdings disclosed that an insecure direct object reference vulnerability in an IIS web server allowed unauthorized access to personal information of numerous independent contractors, including names, dates of birth, contact details, Social Security numbers and driver’s license numbers. The breach affected roughly forty thousand individuals, and a review of the exposed files was completed before notification letters were sent. The company reported that no customer data or financial systems were accessed, business operations continued unaffected, and the FBI has been informed of the incident. While the attacker remains unidentified, RCI stated that the data has not been publicly disseminated and will cooperate with any ensuing investigation.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 19 2026 the unauthorized access to RCI Hospitality Holdings’ systems began, according to an internal investigation that concluded earlier in April. On March 23 the company’s RCI Internet Services subsidiary identified an insecure direct object reference (IDOR) vulnerability in an IIS web server that allowed attackers to alter a parameter in a URL or request and retrieve records without proper authorization checks. The vulnerability was disclosed to the Securities and Exchange Commission in a mid‑April filing, which noted that the exposure involved personal information of “numerous” independent contractors, including names, dates of birth, contact details, Social Security numbers and driver’s license numbers. RCI stated that, to its knowledge, the unauthorized actor had not publicly disseminated the data and that no customer information or financial systems were accessed. The company also reported that its business operations continued unaffected and that it did not anticipate a material impact from the incident.

Following the discovery, RCI initiated a review of the compromised files, which was completed on May 13 2026. Notification letters were subsequently sent to the affected individuals, and the Federal Bureau of Investigation was informed of the breach. RCI indicated its willingness to cooperate with any ensuing FBI investigation. In a June 6 2026 update the company disclosed that the breach affected roughly 40,000 individuals, a figure that had been uncertain in the earlier April disclosure. No known ransomware group has claimed responsibility for the attack, and the identity of the threat actor remains unknown.

The response actions taken by RCI included securing the vulnerable IIS web server, completing the forensic review of the stolen data, issuing breach notifications to all impacted parties, and maintaining communication with law‑enforcement authorities. The company emphasized that its operational functions were not disrupted and that it does not expect the incident to result in significant financial or reputational harm. RCI continues to monitor the situation and to assist the FBI as required.

Sources

Sources available to members: 2 sources.

CSIDB