RCI HOSPITALITY HOLDINGS, INC. 8-K
Research Summary
AI-generated summary
RCI Hospitality Reports Cybersecurity Incident Exposing Contractor Data
What Happened RCI Hospitality Holdings, Inc. (RICK) announced a cybersecurity incident the company discovered on March 23, 2026, stemming from activity that began on March 19, 2026. An investigation concluded April 7, 2026, and found a potential insecure direct object reference vulnerability on the company’s Internet Information Services (IIS) web server. The company engaged third‑party cybersecurity firms, expanded multifactor authentication, and disabled external access to the IIS to remediate the issue. RCI says certain personal information for numerous independent contractors — including names, contact details, dates of birth, Social Security numbers, and driver’s license numbers — was accessed without authorization. To the company’s knowledge, the data has not been publicly disseminated and no customer information or financial systems were accessed.
Key Details
- Discovery and timeline: incident began March 19, 2026; discovered March 23, 2026; investigation concluded April 7, 2026.
- Data types accessed: contractor names, contact information, dates of birth, Social Security numbers, and driver’s license numbers.
- Remediation and response: engaged third‑party cybersecurity firms, expanded multifactor authentication, and disabled external IIS access.
- Financial/operational impact: company believes the incident will not have a material adverse effect on operations but will incur related expenses and carries cybersecurity insurance (subject to deductibles, exclusions, and limits).
Why It Matters For investors, the filing confirms a data security incident that affects contractor personal data and will generate investigation and remediation costs and potential regulatory or notification obligations. RCI states its key systems for customers and finances were not accessed and expects no material operational impact, and it has cyber insurance that may cover many costs. Monitor for follow‑up disclosures about the scope of affected individuals, any regulatory actions, legal claims, insurance recoveries, or changes to the company’s assessment of materiality.
Loading document...