Summary
- Environment: Date RCI discovered the incident after becoming aware of a network disruption.
- Operational impact: No outage or recovery duration quantified
- Financial impact: No public cost estimate
- Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.
What happened
Unauthorized access to personal information on systems operated by RCI Internet Services, a subsidiary of RCI Hospitality Holdings. [1]
Impact
Personal information concerning independent contractors was accessed without authorization. [1][2][3]
Documented data types include:
- Names — The affected fields varied by individual. [1][2]
- Contact information — RCI Hospitality reported that contact information may have been included. [1][2]
- Passport numbers — The individual-notice sample says information may have included a passport number; fields varied by person. [1][2]
- Driver’s license numbers — The affected fields varied by individual. [1][2]
- Social Security numbers — The affected fields varied by individual. [1][2]
- Dates of birth — RCI Hospitality reported that dates of birth may have been included. [1][2]
A cited record reports 201 individuals (Massachusetts residents listed in incident record 2026-908; this is not a national total; as of 2026-06-04). [1][2][3]
RCI reported no evidence of misuse or attempted misuse in its May 28 notice, while its earlier SEC filing said the unauthorized actor had not publicly disseminated the data to the company’s knowledge. [1][2]
Timeline
Activity began
Unauthorized access to personal information on systems operated by RCI Internet Services, a subsidiary of RCI Hospitality Holdings.
[1]Discovery
Date RCI discovered the incident after becoming aware of a network disruption.
[1]Documented event
RCI investigation concludes is recorded on this date.
[1]Documented event
RCI confirms personal information in affected files is recorded on this date.
[2]Documented event
Date printed on the affected-individual notice sample.
[2]Briefing updated
This briefing was last reviewed and updated on August 9, 2026.
Threat Group & Attack Vector
RCI Hospitality reported learning that a potential insecure direct object reference vulnerability was present on the subsidiary’s Internet Information Services web server. [1]
Actors
- No threat actor group has been identified in the reviewed public evidence.
TTPs
- No specific MITRE ATT&CK technique is currently mapped for this case.
Response
RCI confirmed that the notification recipient’s personal information was contained in the potentially affected files. RCI Hospitality reported that no customer information or financial systems were accessed. RCI Hospitality reported that the incident did not affect company business operations and was not expected to have a material adverse operational effect. Personal information concerning numerous independent contractors was accessed without authorization. RCI reported engaging third-party cybersecurity firms, expanding multifactor authentication, disabling external IIS access, notifying the FBI, and offering identity-protection services through IDX. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1][2]
