---
title: "RCI Internet Services contractor data incident"
description: "Evidence-backed account of RCI Internet Services contractor data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/rci-internet-services-contractor-data-incident-2026"
markdown_url: "https://www.ally.security/incidents/rci-internet-services-contractor-data-incident-2026.md"
stix_url: "https://www.ally.security/incidents/rci-internet-services-contractor-data-incident-2026/stix.json"
---

# RCI Internet Services contractor data incident

Unauthorized access to personal information on systems operated by RCI Internet Services, a subsidiary of RCI Hospitality Holdings. Personal information concerning independent contractors was accessed without authorization.

Last modified Aug 9, 2026 · 3 sources

## Summary

- **Environment:** Date RCI discovered the incident after becoming aware of a network disruption.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to personal information on systems operated by [RCI Internet Services](https://www.rciinternet.com/), a subsidiary of RCI Hospitality Holdings. [1](#source-1)

## Impact

Personal information concerning independent contractors was accessed without authorization. [1](#source-1) [2](#source-2) [3](#source-3)

Documented data types include:

- Names — The affected fields varied by individual. [1](#source-1) [2](#source-2)
- Contact information — RCI Hospitality reported that contact information may have been included. [1](#source-1) [2](#source-2)
- Passport numbers — The individual-notice sample says information may have included a passport number; fields varied by person. [1](#source-1) [2](#source-2)
- Driver's license numbers — The affected fields varied by individual. [1](#source-1) [2](#source-2)
- Social Security numbers — The affected fields varied by individual. [1](#source-1) [2](#source-2)
- Dates of birth — RCI Hospitality reported that dates of birth may have been included. [1](#source-1) [2](#source-2)

A cited record reports 201 individuals (Massachusetts residents listed in incident record 2026-908; this is not a national total; as of 2026-06-04). [1](#source-1) [2](#source-2) [3](#source-3)

RCI reported no evidence of misuse or attempted misuse in its May 28 notice, while its earlier SEC filing said the unauthorized actor had not publicly disseminated the data to the company's knowledge. [1](#source-1) [2](#source-2)

## Timeline

### March 19, 2026 — Activity began

Unauthorized access to personal information on systems operated by RCI Internet Services, a subsidiary of RCI Hospitality Holdings. [1](#source-1)

### March 23, 2026 — Discovery

Date RCI discovered the incident after becoming aware of a network disruption. [1](#source-1)

### April 7, 2026 — Documented event

RCI investigation concludes is recorded on this date. [1](#source-1)

### May 13, 2026 — Documented event

RCI confirms personal information in affected files is recorded on this date. [2](#source-2)

### May 28, 2026 — Documented event

Date printed on the affected-individual notice sample. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

RCI Hospitality reported learning that a potential insecure direct object reference vulnerability was present on the subsidiary's Internet Information Services web server. [1](#source-1)

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

RCI confirmed that the notification recipient's personal information was contained in the potentially affected files. RCI Hospitality reported that no customer information or financial systems were accessed. RCI Hospitality reported that the incident did not affect company business operations and was not expected to have a material adverse operational effect. Personal information concerning numerous independent contractors was accessed without authorization. RCI reported engaging third-party cybersecurity firms, expanding multifactor authentication, disabling external IIS access, notifying the FBI, and offering identity-protection services through IDX. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1) [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/rci-internet-services-contractor-data-incident-2026/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Current Report on Form 8-K — March 2026 cybersecurity incident

official · RCI Hospitality Holdings, Inc.

<https://www.sec.gov/Archives/edgar/data/935419/000162828026024806/rick-20260407.htm>

<a id="source-2"></a>

### Notice of Data Security Incident or Breach — California sample

official · RCI Internet Services, Inc.

<https://oag.ca.gov/system/files/RCI%20Internet%20Services%20Inc.%20-%20Notice%20of%20Data%20Event%20-%20%28CA%29_0.pdf>

<a id="source-3"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Resulted In · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: RCI confirms personal information in affected files
2. **Occurred At · 100% confidence · current**  
   RCI investigation concludes: 2026-04-07
3. **Subsidiary Of · 100% confidence · current**  
   RCI Internet Services, Inc.: RCI Hospitality Holdings, Inc.
4. **Resulted In · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: RCI reported no evidence of misuse or attempted misuse in its May 28 notice, while its earlier SEC filing said the unauthorized actor had not publicly disseminated the data to the company's knowledge.
5. **Resulted In · 100% confidence · current**  
   RCI investigation concludes: RCI Hospitality reported learning that a potential insecure direct object reference vulnerability was present on the subsidiary's Internet Information Services web server.
6. **Affected Individual Count · 100% confidence · current**  
   RCI independent-contractor personal data exposure: 201 individual
7. **Exposed Data Category · 90% confidence · current**  
   RCI independent-contractor personal data exposure: Names
8. **Resulted In · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: RCI investigation concludes
9. **Resulted In · 100% confidence · current**  
   RCI confirms personal information in affected files: RCI confirmed that the notification recipient's personal information was contained in the potentially affected files.
10. **Resulted In · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: RCI independent-contractor personal data exposure
11. **Exposed Data Category · 90% confidence · current**  
   RCI independent-contractor personal data exposure: Contact information
12. **Resulted In · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: RCI Hospitality reported that no customer information or financial systems were accessed.
13. **Exposed Data Category · 90% confidence · current**  
   RCI independent-contractor personal data exposure: Passport numbers
14. **Exposed Data Category · 90% confidence · current**  
   RCI independent-contractor personal data exposure: Driver's license numbers
15. **Began At · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: 2026-03-19
16. **Resulted In · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: RCI affected-individual notification
17. **Resulted In · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: RCI Hospitality reported that the incident did not affect company business operations and was not expected to have a material adverse operational effect.
18. **Affected Organization · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: RCI Internet Services, Inc.
19. **Occurred At · 100% confidence · current**  
   RCI confirms personal information in affected files: 2026-05-13
20. **Exposed Data Category · 90% confidence · current**  
   RCI independent-contractor personal data exposure: Social Security numbers
21. **Resulted In · 100% confidence · current**  
   RCI independent-contractor personal data exposure: Personal information concerning numerous independent contractors was accessed without authorization.
22. **Exposed Data Category · 90% confidence · current**  
   RCI independent-contractor personal data exposure: Dates of birth
23. **Resulted In · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: RCI reported engaging third-party cybersecurity firms, expanding multifactor authentication, disabling external IIS access, notifying the FBI, and offering identity-protection services through IDX.
24. **Occurred At · 100% confidence · current**  
   RCI affected-individual notification: 2026-05-28
25. **Discovered At · 100% confidence · current**  
   March 2026 RCI Internet Services cybersecurity incident: 2026-03-23

</details>
