← Blog

RCI Hospitality Data Breach Hits 40,000 Contractors After IDOR Flaw

Share on X

Adult nightclub operator RCI Hospitality Holdings disclosed to Maine authorities in June 2026 that more than 40,000 individuals were affected by a data breach at subsidiary RCI Internet Services.

How the breach happened

RCI told the SEC in April 2026 that an insecure direct object reference (IDOR) on a March 23 IIS web server let attackers access files containing independent-contractor names, contact information, dates of birth, Social Security numbers, and driver’s license numbers. A file review completed May 13; the FBI was notified.

What contractors should do

  • Freeze credit and enable fraud alerts if you received a notice.
  • Watch for W-2 or 1099 phishing using real contractor details.
  • Report suspicious identity documents to the FTC and your state AG.

Canonical record: RCI Hospitality 2026 on BreachHistory.

Sources: SecurityWeek