RCI Internet Services
bd_84021bb308396ab6 · schema v1 · pii pii-v1
Full breach record for RCI Internet Services →RCI Internet Services, Inc., a subsidiary of RCI Hospitality Holdings, Inc., disclosed a cybersecurity incident occurring March 19-23, 2026. An unauthorized actor exploited an insecure direct object reference (IDOR) vulnerability on the company's Internet Information Services (IIS) web server. The incident resulted in the unauthorized access of independent contractors' personal information, including names, contact details, dates of birth, Social Security numbers, and driver's license numbers. The company engaged third-party cybersecurity firms, enhanced security posture by expanding multifactor authentication, and disabled external access to the IIS. No customer or financial system data was accessed.
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- bd_a70b8f9e2881284fIndiana State AGfiled 2026-05-28(45d gap)Candidate
- bd_5a66b0e3099e927cCalifornia State AGfiled 2026-05-29(46d gap)Verified
- bd_a36612655039e10fNew Hampshire State AGfiled 2026-06-01(49d gap)Verified
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/935419/000162828026024806/rick-20260407.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Apr 13, 2026
- Raw hash
- 3810aea5e25793d8afd4228e9f4b64cad48ebe36eb28b9e309b3f0f8e088a18f
Source filing
Reporting entity
- Name
- RCI HOSPITALITY HOLDINGS, INC.norm: rci hospitality
- SEC CIK
- 0000935419
Victim entity
- Name
- RCI Internet Servicesnorm: rci internet
Incident
- Discovered
- Mar 23, 2026
- Materiality determined
- Apr 7, 2026
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 21 days(21 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 6d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Apr 7, 2026→ Filed: Apr 13, 20266d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.