Business Context and Reporting Period
Company: RCI Hospitality Holdings, Inc. (Ticker: RICK)
Filing Type: Form 8-K (Current Report)
Date of Report: April 7, 2026
Event Date: March 19, 2026 (Incident Start) to April 7, 2026 (Investigation Conclusion)
Context: The Company reported a cybersecurity incident affecting its subsidiary, RCI Internet Services, Inc.
Key Financial Metrics
The filing does not provide specific revenue, profit, cash flow, margin, debt, or liquidity figures. This report focuses on a non-financial event (cybersecurity incident). The Company noted it will incur expenses in the fiscal year related to the event but did not quantify these costs.
Material Changes and Incident Details
- Incident Nature: A potential insecure direct object reference vulnerability on an Internet Information Services (IIS) web server.
- Timeline: Incident began March 19, 2026; discovered March 23, 2026; investigation concluded April 7, 2026.
- Impact on Operations: No impact on business operations.
- Data Compromised: Personal information of numerous independent contractors, including names, contact information, dates of birth, Social Security numbers, and driver's license numbers.
- Data Not Compromised: Customer information and financial systems were not accessed.
- Remediation: Enhanced technical security posture, expanded multifactor authentication, and disabled external access to the IIS.
Outlook, Risks, and Management Commentary
Management Assessment: The Company believes the incident will not have a material adverse effect on its business operations. The unauthorized actor has not publicly disseminated the data to the Company's knowledge.
Financial Implications: The Company expects to incur direct and indirect expenses in the fiscal year. It maintains a comprehensive cybersecurity insurance policy covering response, investigation, remediation, regulatory actions, business interruption, and legal proceedings, subject to deductibles, exclusions, and limits.
Risks and Contingencies:
- Potential regulatory inquiries and litigation.
- Legal, reputational, and financial risks.
- Impact on relationships with employers, employees, and independent contractors.
- Possibility of discovering additional information during the ongoing investigation.
Investor Verification Checklist
- Verify the scope of "numerous independent contractors" affected to assess potential notification costs and reputational impact.
- Review the specific deductibles, exclusions, and limits of the Company's cybersecurity insurance policy.
- Monitor for future filings regarding regulatory actions or litigation stemming from the incident.
- Confirm if the "insecure direct object reference" vulnerability has been fully patched across all systems.
- Check subsequent 10-Q or 10-K filings for quantification of incident-related expenses.