HackingData ExfiltratedCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
RCI Internet Services
bd_5a66b0e3099e927c · schema v1 · pii pii-v1
Full breach record for RCI Internet Services →RCI Internet Services, Inc. notified the California Attorney General of a data security incident. On March 23, 2026, the company became aware of a network disruption. Investigation revealed that certain files were accessed and acquired without authorization on March 19, 2026. Affected data may include names, Social Security numbers, driver's license numbers, and passport numbers. The company engaged cybersecurity experts, notified the FBI, and is offering identity protection services to affected individuals.
California clockDiscovered Mar 23, 2026 → Notified May 28, 202666d ✗ CA 30-day late10 weeks discovery → filing
This filing is one of 4 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a70b8f9e2881284fIndiana State AGfiled 2026-05-28(1d gap)Candidate
- bd_a36612655039e10fNew Hampshire State AGfiled 2026-06-01(3d gap)Verified
- bd_84021bb308396ab6SEC 8-Kfiled 2026-04-13(46d gap)Verified
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-624171
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 29, 2026
- Raw hash
- 969a7dc3d0c791790a7881b124011b818611d436b1da90ce1a050428b7f9eb83
Reporting entity
- Name
- RCI Discovernorm: rci discover
- Domain
- discover.rci.com
Victim entity
- Name
- RCI Internet Servicesnorm: rci internet
Incident
- Discovered
- Mar 23, 2026
- Materiality determined
- —
- Notification sent
- May 28, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unknown
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- External
- Regulator citations
- Notified the Federal Bureau of Investigation
Compliance
- Time to disclose
- 10 weeks(67 days from discovery to filing)
- Compliance flags
- CA 30-day late · 66dCA AG copy ≤15d · 1d
- Discovery-date grounding
- letter-groundedThe discovery date is the detection date narrated in the notification letter — the defensible tier.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Mar 23, 2026→ Notified: May 28, 202666d 30 calendar days CA 30-day late California Consumers notified: May 28, 2026→ AG copy submitted: May 29, 20261d 15 calendar days CA AG copy ≤15d
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.