RCI Internet Services, Inc., a subsidiary of RCI Hospitality Holdings, Inc., disclosed a cybersecurity incident occurring March 19-23, 2026. An unauthorized actor exploited an insecure direct object reference (IDOR) vulnerability on the company's Internet Information Services (IIS) web server. The incident resulted in the unauthorized access of independent contractors' personal information, including names, contact details, dates of birth, Social Security numbers, and driver's license numbers. The company engaged third-party cybersecurity firms, enhanced security posture by expanding multifactor authentication, and disabled external access to the IIS. No customer or financial system data was accessed.