DisclosureLens
FEDERALItem 8.01 · voluntaryHackingTechnologyInformationIdentity (basic)Government IDMediumContained

RCI Internet Services, Inc.

bd_84021bb308396ab6 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Mar 23, 2026

Filed

Apr 13, 2026

To disclose

21 days

Affected

Not disclosed

Linked

8 filings

Confidence

66%
Full breach record for RCI Internet Services, Inc.2 incidents on file

RCI Internet Services, Inc., a subsidiary of RCI Hospitality Holdings, Inc., disclosed a cybersecurity incident that started March 19, 2026 and was discovered March 23, 2026. Its investigation found that a potential insecure direct object reference vulnerability was present on the company's internet information services (IIS) web server. The company believes independent contractors' personal information, including names, contact details, dates of birth, Social Security numbers, and driver's license numbers, was accessed without authorization. The company engaged third-party cybersecurity firms, enhanced security posture by expanding multifactor authentication, and disabled external access to the IIS. No customer information or financial systems were accessed.

Incident timeline

undetected · 4 days
discovery → filing · 21 days

Mar 19, 2026

Begins

Mar 23, 2026

Discovered

Apr 13, 2026

Filed

vs. sector median

16 wks faster

This filing is one of 8 about the same incident.View merged incident

Linked disclosures

Why this link?

Regulatory filings (7) · sorted by filing gap

Show 3 more filingsup to 52d gap

Filing propagation · 8 filings · 7 states

View merged incident ↗

Pattern: first filing Apr 13, last Jun 4 (MA) — a 52-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statementThis record

Unlocks: materiality, stated response, full audit trail. Ceiling removed.