Menu
Browse

Cyber Incident Victim: RCI Hospitality Holdings

Date:

Mar 2026

Location:

United States of America

Summary

RCI Hospitality Holdings disclosed that its RCI Internet Services subsidiary identified an insecure direct object reference vulnerability in an IIS web server that allowed unauthorized access to personal information of numerous independent contractors, including names, dates of birth, contact details, Social Security numbers and driver’s license numbers. The breach did not involve customer data or financial systems, and the company said business operations were unaffected and no material impact is expected. Review of the compromised files was completed, the FBI has been notified, and no known ransomware group has claimed responsibility. Approximately forty thousand individuals were affected, and the unauthorized actor has not publicly disseminated the data.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 19, 2026, unauthorized access began to an IIS web server operated by RCI Internet Services, a subsidiary of RCI Hospitality Holdings. On March 23, 2026, the subsidiary discovered an insecure direct object reference (IDOR) vulnerability in that server. The vulnerability allowed an attacker to change identifiers in URLs or requests to access personal information without proper authorization. RCI Hospitality reported the discovery to the SEC in mid‑April 2026. An investigation concluded earlier in April 2026 determined that the incident started on March 19 and was contained after the vulnerability was identified.

Cyber Incident Image

The exposed data consisted of personal information of numerous independent contractors, including names, dates of birth, contact information, Social Security numbers, and driver’s license numbers. RCI Hospitality stated that no customer information or financial systems were accessed. Review of the stolen files was completed on May 13, 2026, after which notification letters were sent to affected individuals. The company later disclosed that roughly 40,000 individuals were impacted by the breach. RCI Hospitality noted that its business operations were not affected and it did not believe the incident would have a material impact on the company.

RCI Hospitality informed the FBI of the breach and said it would cooperate with any resulting investigation. To the company’s knowledge, the unauthorized actor had not publicly disseminated the data. No known ransomware group or cybercrime group had taken credit for the attack. The company described the incident as unauthorized access and acknowledged a small possibility that it could be related to activities by security researchers, though no attribution was made. RCI Hospitality continued to monitor the situation and work with authorities as the breach response proceeded.

Sources
Sources available to members
2 sources