Apple American Group Data Breach Class Action Lawsuit Investigation

Data breach law firm Abington Cole + Ellery is investigating potential legal claims related to the Apple American Group data breach, which reportedly affected thousands of individuals and may have exposed Social Security Numbers, Government ID Numbers, Financial Account Codes, Credit and Debit Account Information, Health Records, and Biometric Information.


JOIN THIS INVESTIGATION: If you are interested in potentially volunteering to serve as a class representative in a class action lawsuit against Apple American Group, please submit your information to be considered:

You may also open the form here: Apple American Group Data Breach Lawsuit Form. An attorney-client relationship is not formed by submitting information through this website.

Apple American Group Data Breach: Key Facts

Company: Apple American Group
Location: Independence, Ohio
Incident Type: Data Breach
Number Affected: THOUSANDS -- TOTAL NOT YET PUBLICLY CONFIRMED
Data Involved: Social Security Numbers, Government ID Numbers, Financial Account Codes, Credit and Debit Account Information, Health Records, and Biometric Information
Date Began: April 8, 2026
Date Discovered: April 9, 2026
Date Ended: April 9, 2026
Notice Date: August 18, 2026
Credit Monitoring: 12 Months of CyberScout credit monitoring and identity protection services
Status: Class Action Lawsuit Investigation


What happened in the Apple American Group data breach?

Apple American Group LLC and Apple American Group II, LLC, the related Applebee’s franchise operators headquartered at 6200 Oak Tree Boulevard, Suite 250, in Independence, Ohio, issued formal notices dated August 18, 2026, regarding a cybersecurity incident that may have affected certain personal information. The companies, which operate under the broader Flynn Group structure, directed the notices through Cyberscout of Suwanee, Georgia. The correspondence states that there is currently no indication of identity theft or fraud connected to the event.

On April 9, 2026, the companies detected suspicious activity on their network and immediately took steps to secure affected systems. A subsequent investigation established that an unknown actor had gained access to certain servers between April 8 and April 9, 2026, and during that brief window had accessed or acquired specific files. A detailed review of those files later confirmed that information belonging to some current or former employees could have been present. The precise categories of data were not itemized in the public-facing notice language beyond reference to details supplied in the course of employment.

Following the discovery, the companies conducted a comprehensive forensic examination, strengthened existing safeguards, and continued monitoring of their security controls. Individual notifications began in mid-August 2026. As a precautionary measure, Apple American Group LLC and Apple American Group II, LLC are providing twelve months of complimentary credit monitoring and identity-theft protection services through CyberScout, a TransUnion company. Eligible individuals must activate the service themselves within ninety days of the notice date using a unique enrollment code supplied in their letter.

The notice further directs recipients to standard consumer-protection resources, including free annual credit reports available at annualcreditreport.com, the placement of fraud alerts or credit freezes with Equifax, Experian, and TransUnion, and guidance from the Federal Trade Commission. State-specific contact information is included for residents of the District of Columbia, Maryland, New Mexico, New York, North Carolina, and Rhode Island. The Rhode Island section notes that approximately 4,954 residents of that state may have been affected. The companies’ legal department in Independence, Ohio, remains available for additional inquiries during standard business hours. Apple American Group Submitted Breach Notification Sample (California)


How did the Apple American Group breach occur?

The notice provides no additional technical details regarding the method of unauthorized access (such as the specific vulnerability, phishing, or other vector employed). Apple American Group Submitted Breach Notification Sample (California)


When did the Apple American Group breach occur?

The unauthorized access that constitutes the Apple American Group LLC and Apple American Group II, LLC data breach occurred between April 8, 2026, and April 9, 2026. According to the official Notice of Data Event dated August 18, 2026: On April 9, 2026, the companies became aware of suspicious network activity. An investigation determined that an unknown actor accessed certain servers between April 8, 2026, and April 9, 2026, and during that period accessed or acquired certain files. Apple American Group Submitted Breach Notification Sample (California)


How many people were affected by the Apple American Group breach?

The total number of individuals affected by the Apple American Group LLC and Apple American Group II, LLC data breach has not been publicly disclosed. Confirmed public state figures: Vermont: 2,992 residents affected (Reported to the Vermont Attorney General on August 18, 2026. Categories listed: Social Security Numbers, Government ID Numbers, Financial Account Codes, Credit and Debit Account Info, Health Records, Biometric Information.) Rhode Island: Approximately 4,954 residents may be impacted (Stated in the companies’ own Notice of Data Event.)


What information was exposed in the Apple American Group breach?

  • According to the official Notice of Data Event issued by Apple American Group LLC and Apple American Group II, LLC on August 18, 2026, the following categories of personal information may have been present in the files accessed or acquired during the incident (Vermont Security Breach Notices):
    • Social Security Numbers
    • Government ID Numbers
    • Financial Account Codes
    • Credit and Debit Account Information
    • Health Records
    • Biometric Information
    The notice states that the specific information involved varied by individual and related to details provided during the course of employment.

Has Apple American Group offered free credit monitoring and/or identity theft protection services?

Yes. According to the official Notice of Data Event issued by Apple American Group LLC and Apple American Group II, LLC on August 18, 2026, the companies are offering affected individuals complimentary access to credit monitoring and identity protection services through CyberScout. Apple American Group Submitted Breach Notification Sample (California)

The services consist of 12 months of Single Bureau Credit Monitoring, Single Bureau Credit Report, and Single Bureau Credit Score protection at no cost. Enrollment instructions and a promotional code are provided in the individual notice letters. Individuals may activate the services by contacting CyberScout using the details supplied in the letter.


Apple American Group data breach timeline:

Date Event
April 8–9, 2026 An unknown actor accessed certain servers belonging to Apple American Group LLC and Apple American Group II, LLC and accessed or acquired certain files during this period.
April 9, 2026 The companies became aware of suspicious network activity. They promptly took steps to secure their systems and launched a comprehensive investigation with the assistance of third-party specialists to determine the nature and scope of the activity.
Following the detection (April–August 2026) A detailed review of the involved files was conducted to identify the types of information contained in the files and the individuals to whom that information related.
August 18, 2026 The companies began issuing written notices to individuals whose information may have been present in the involved files. Concurrently, regulatory notifications were submitted to state Attorneys General, including a filing with the Vermont Attorney General reporting 2,992 Vermont residents affected and confirmation in the companies’ notice that approximately 4,954 Rhode Island residents may have been impacted.
Within ninety (90) days from the date of the letter. According to the official Notice of Data Event, individuals must enroll in the complimentary credit monitoring services within ninety (90) days from the date of the letter. Enrollment is completed online at the CyberScout activation link provided in the notice, using the unique code included in each individual’s letter.

Who is Apple American Group?

Apple American Group LLC and Apple American Group II, LLC are affiliated limited liability companies that operate as franchisees of Applebee’s Neighborhood Grill & Bar restaurants. Both entities maintain their principal place of business at 6200 Oak Tree Boulevard, Suite 250, in Independence, Ohio, and form part of the Flynn Group portfolio of restaurant operations. Founded in the late 1990s, Apple American Group LLC has developed into the largest franchisee within the Applebee’s system, with Apple American Group II, LLC supporting related restaurant holdings; together they oversee a significant number of Applebee’s locations spanning multiple states across the United States.


What should you do if you received a Apple American Group data breach letter?

If you received a data breach notification letter from Apple American Group LLC or Apple American Group II, LLC, you should first enroll in the complimentary credit monitoring and identity protection services being offered. The companies are providing twelve months of Single Bureau Credit Monitoring, Credit Report, and Credit Score services through CyberScout at no cost. Use the enrollment instructions and promotional code included in your letter to activate the service promptly, as the enrollment period is limited.

Carefully review the letter to confirm which specific categories of your personal information may have been involved, and retain the letter for your records. In addition, monitor your bank, credit card, and other financial accounts regularly for any unfamiliar activity, and obtain free copies of your credit reports from AnnualCreditReport.com or directly from the credit bureaus to check for unauthorized accounts or inquiries. Continue this monitoring even after the free service period ends.

You may also wish to place a free one-year fraud alert by contacting any one of the three major credit bureaus—Equifax, Experian, or TransUnion—which will then notify the other two, or consider placing a security freeze on your credit files with all three bureaus for stronger protection. Remain alert to possible phishing attempts, as neither Apple American Group nor CyberScout will contact you to request sensitive details such as your full Social Security number or bank account information outside the enrollment process described in the letter.

Should you discover any signs of identity theft or suspicious activity, report it to the Federal Trade Commission at IdentityTheft.gov, notify the relevant financial institutions and credit bureaus, and consider filing a report with local law enforcement. The notice letter itself contains contact information for CyberScout as well as state-specific resources that may assist you further.


Apple American Group Data Breach Notice

The notice describes the Apple American Group data breach, including the type of information that may have been involved and the steps offered to affected individuals.

Open the Apple American Group Data Breach Notice in a New Tab


Sources and additional information about the data breach:


Class Action FAQ

A class action lawsuit is a case brought on behalf of a group of people who were harmed in a similar way by the same company or organization.

A class representative, sometimes called a named plaintiff or lead plaintiff, is a person who volunteers to bring the lawsuit on behalf of the larger group. They help represent the interests of everyone in the class. There may be more than one class representative in a class action.

A person who was harmed may start a class action if many other people were harmed in a similar way.

Usually, no. In many class action cases, the lawyers are paid only if the case is successful.

Sometimes you do not need to do anything. Other times, you may need to submit a claim form by a deadline to receive money or benefits.


Infographic summarizing the Apple American Group data breach, including the number of affected individuals, the categories of information involved, and the publicly confirmed reporting timeline.
Apple American Group data breach infographic summarizing the number of people affected, the types of information involved, and the publicly confirmed timeline. Information current as of August 18, 2026.


About This Data Breach Resource

This page was created to give affected individuals and researchers a clear, comprehensive explanation of the Apple American Group data breach. It summarizes what is currently known about the incident, including the timeline, how the breach was discovered, the types of information involved, the number of people affected when available, important notice dates, and steps individuals may want to take after receiving a data breach notification.

This resource is independently written and organized to help readers understand the breach without having to review multiple notices, state attorney general filings, company statements, and related materials. When available, this page relies on primary sources and identifies key facts, unanswered questions, and updates as new information becomes public.

This page is especially relevant for readers searching for information about the Apple American Group data breach, Apple American Group data breach notice, Apple American Group class action investigation, what information was exposed, how many people were affected, and what affected individuals should do next.

Abington Cole + Ellery reviews data breach incidents involving sensitive personal information, financial information, and protected health information. This page is intended to help affected individuals understand the publicly reported facts, the types of information that may have been involved, and practical steps that may reduce the risk of identity theft or medical identity theft.

The information on this webpage is provided for general informational purposes only and does not constitute legal advice. Nothing on this page should be relied upon as legal advice for any particular situation. Submitting information through this page does not create an attorney-client relationship.

For more information about steps you can take to possibly reduce the risk harm arising from a data breach, please review the following article: What are some steps you can take if you've been the victim of a data breach?

This website is not associated with nor authorized by Apple American Group or any affiliated companies. If you have received any other data breach notifications, you may want to review Abington Cole + Ellery's current list of data breach investigations.