Adult nightclub operator RCI Hospitality Holdings disclosed to Maine authorities in June 2026 that more than 40,000 individuals were affected by a data breach at subsidiary RCI Internet Services.
How the breach happened
RCI told the SEC in April 2026 that an insecure direct object reference (IDOR) on a March 23 IIS web server let attackers access files containing independent-contractor names, contact information, dates of birth, Social Security numbers, and driver’s license numbers. A file review completed May 13; the FBI was notified.
What contractors should do
- Freeze credit and enable fraud alerts if you received a notice.
- Watch for W-2 or 1099 phishing using real contractor details.
- Report suspicious identity documents to the FTC and your state AG.
Canonical record: RCI Hospitality 2026 on BreachHistory.
Sources: SecurityWeek