RCI Internet Services Data Breach Exposes Social Security Numbers and Passport Data

Other Commercial data breach illustration
Breach Discovery: March 2026Breach Notification: May 2026

What Happened in the RCI Internet Services Data Breach?

RCI Internet Services recently told affected individuals about a data security incident involving their personal information. The company noticed a disruption on its network on March 23, 2026. As a result, it launched an investigation right away and brought in outside cybersecurity experts to help.

That investigation revealed something more serious than a simple technical glitch. According to the notification letter, an unauthorized party accessed and took certain files on March 19, 2026. This means the intrusion actually happened a few days before RCI Internet Services noticed the disruption on its systems.

Because the stolen files needed careful review, the process took time. RCI Internet Services confirmed on May 13, 2026 that specific individuals’ personal information was contained in the compromised data. This confirmation triggered the formal notification process that followed weeks later.

The company also reported the incident to the Federal Bureau of Investigation and says it will cooperate with any resulting law enforcement investigation. As of the notification letter, RCI Internet Services stated it has no evidence that anyone has misused or attempted to misuse the exposed information. However, that assurance does not eliminate the risk that stolen data could surface later.

Who was affected?

RCI Internet Services sent breach notification letters directly to individuals whose personal information appeared in the compromised files. The letter does not specify whether these individuals were customers, employees, or another group connected to the company. It also does not state a total number of people affected.

Because the notification does not disclose an exact count, the full scope of this breach hasn’t been publicly disclosed. What is clear is that the company considered the risk serious enough to offer identity protection services and notify the FBI. Anyone who receives a letter from RCI Internet Services should assume their information was part of the exposed files.

What Information Was Potentially Exposed?

The data involved in this breach includes some of the most sensitive categories of personal information that exist. Unlike breaches limited to email addresses or usernames, this incident touched documents that identity thieves specifically target.

  • Full name
  • Social Security number
  • Driver’s license number
  • Passport number

This combination of data is particularly concerning because it includes government-issued identification numbers alongside Social Security numbers. As a result, criminals could use this information to open new financial accounts, file fraudulent tax returns, or even create fake identification documents. Because passport numbers were involved, there’s also a risk of international identity misuse, including fraudulent travel documents.

In addition, driver’s license numbers can be used to pass identity checks at financial institutions or government offices. When combined with a Social Security number, this data gives criminals nearly everything needed to impersonate someone convincingly. Therefore, affected individuals should treat this breach as a high-risk event, even though RCI Internet Services has not reported confirmed misuse so far.

What is the company doing?

Once RCI Internet Services discovered the network disruption, it acted quickly to investigate and contain the situation. The company engaged independent cybersecurity experts to determine what happened and which files were affected. It also implemented additional security measures aimed at reducing the chances of a similar incident happening again.

Beyond internal remediation, RCI Internet Services notified the FBI and says it will support any investigation that follows. The company is also offering complimentary identity protection services through IDX, a provider specializing in consumer identity protection. These services include credit monitoring, dark web monitoring, a $1 million identity fraud loss reimbursement policy, and identity theft recovery support. Individuals have until August 28, 2026 to enroll using the code provided in their notification letter.

What Should Affected Individuals Do?

Enroll in the Free Identity Protection Services

If you received a letter from RCI Internet Services, you should enroll in the complimentary IDX identity protection services before the August 28, 2026 deadline. This service includes credit monitoring and dark web monitoring, which can alert you if your information appears somewhere it shouldn’t.

Because enrollment requires a unique code from your letter, don’t delay signing up. Missing the deadline could mean losing access to a $1 million fraud reimbursement policy and professional identity recovery support at no cost to you.

Place a Fraud Alert or Credit Freeze

Given that Social Security numbers and driver’s license numbers were exposed, placing a fraud alert or credit freeze is a strong protective step. A fraud alert is free and requires creditors to verify your identity before opening new accounts in your name.

For even stronger protection, consider a security freeze with each of the three major credit bureaus. This blocks lenders from accessing your credit report entirely unless you unlock it, which makes it much harder for identity thieves to open fraudulent accounts.

Monitor Your Credit Reports and Financial Accounts

You should regularly review your credit reports and bank statements for unfamiliar activity. You can request a free credit report from each bureau annually through AnnualCreditReport.com, and checking these reports periodically helps catch fraud early.

If you notice suspicious charges or unfamiliar accounts, report them to your bank immediately. In addition, filing a report with local law enforcement or the FTC creates a record that can help if you need to dispute fraudulent activity later.

Watch for Phishing Attempts

Because your name and identification numbers were exposed, scammers may try to contact you posing as RCI Internet Services or a related institution. Be cautious of unexpected emails, calls, or texts asking you to confirm personal details or click suspicious links.

Instead of responding directly, verify any communication by contacting the company through official channels. This simple habit can prevent scammers from tricking you into handing over even more sensitive information.

Protect Your Passport and Government-Issued IDs

Since your passport and driver’s license numbers were part of this breach, consider monitoring for unusual activity tied to these documents. If you notice signs of misuse, such as unfamiliar accounts opened using your ID, report it right away to the issuing agency.

You may also want to contact the U.S. State Department if you suspect passport-related fraud. Taking these extra precautions can help limit the damage if someone tries to misuse your government identification.



More Information

Official data breach notification from California Attorney General

Related Data Breaches