RCI HOSPITALITY HOLDINGS, INC.
Apr 2026 · Graded Verified · Retail and Consumer · Government record
Incident summary
RCI HOSPITALITY HOLDINGS, INC.Apr 2026
breach at RCI Internet Services, Inc.
Not yet quantified
VVerifiedRCI Internet Services left an insecure direct object reference on its public-facing IIS web server, so the application checked who was logged in but never whether the record requested was actually theirs. Changing a number in the URL was enough to walk out with contractor files on about 40,178 people, Social Security and driver's license numbers included. Its remediation, adding multifactor authentication and cutting external access, names the wall that was never there. Authorization was not breached here; it was never enforced past the login screen.
Retail and Consumer
SEC 8-K, Item 8.01
Initial attack type software vulnerability confirmed · Impact data theft confirmed
About this record
This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.