Applebee’s Franchisee Lawsuit: Apple American Group Data Breach
Questions about this case?
AI Legal Assistant · free · answers in seconds · general information, not legal advice
The Applebee’s franchisee lawsuit in the news is about workers, not diners. Apple American Group, the largest Applebee’s franchisee, says an unknown actor got into its servers on April 8–9, 2026 and took files holding information people gave it as employees. Notice letters went out on August 18, 2026. At least eight proposed class actions followed in federal court in Cleveland. As of October 2026 there is no settlement and no claim form.
Editorially Reviewed — Content reviewed for accuracy using published legal research, government data, and verified court records. See our methodology
Reviewed by Leonard Goldberg, Editor · Last updated
What Happened and What the Lawsuits Say
Apple American Group LLC and Apple American Group II, LLC run Applebee’s restaurants as a franchisee and are part of Flynn Group. In their breach notice the companies say they became aware of suspicious network activity on April 9, 2026, and that an unknown actor “accessed certain servers between April 8, 2026 and April 9, 2026, and accessed or acquired certain files.” The letter says the information involved is what people provided “during the course of your employment.”
Per the company’s filing with the Washington Attorney General, the categories include name, Social Security number, financial account and payment card information, date of birth, driver’s license or other government ID number, medical and health insurance information, biometric data and user account information. Not every person had every field.
The lawsuits allege the companies failed to protect that data, that it was stored without encryption or redaction, and that people were warned only about four months after the breach was found. They plead negligence, negligence per se, breach of implied contract and unjust enrichment. These are allegations; the companies have not been found liable.
Case Details
The cases name Apple American Group LLC and Apple American Group II, LLC and were filed in the U.S. District Court for the Northern District of Ohio in Cleveland — the companies’ support center is in Independence, Ohio. Two reported cases are Lema v. Apple American Group LLC, et al., No. 1:26-cv-02013, and Daniels v. Apple American Group LLC, et al., No. 1:26-cv-02023. Counts differ by source: Top Class Actions, citing Law360, reports at least eight proposed class actions; Hoodline, citing Cleveland.com, reports ten. Plaintiffs reportedly come from Florida, Massachusetts, Georgia, New York, Rhode Island, California and Pennsylvania. We found no public order consolidating the cases as of October 5, 2026.
Status: Early Lawsuits, No Settlement
Follow this case
There's no claim deadline yet. We'll email you if a settlement opens a claim period.
Who Is Affected
The proposed classes cover people whose information was compromised in the breach, including everyone who received a notice letter. In practice that means current and former employees of the Apple American Group restaurants — the letter ties the data to employment. Eating at an Applebee’s does not put you in this case, and Applebee’s locations run by other franchisees are not part of it.
The total count has not been confirmed in an official source we could check. State filings show 20,653 Washington residents, 16,241 in Massachusetts, 6,790 in New Hampshire, about 4,954 in Rhode Island and 2,992 in Vermont. The breach tracker ClaimDepot puts the total at 282,573 — treat that as unverified.
Your letter is the test. It is dated August 18, 2026 and comes from “Apple American Group LLC and Apple American Group II, LLC, c/o Cyberscout.” Keep it and the envelope. You do not need to sign up anywhere to be in a class.
Is There Money?
For context only, not a prediction: employee-data breach settlements usually combine reimbursement of documented losses, a smaller flat payment for people who document nothing, and credit monitoring. A recent example is the Jack’s Family Restaurants payroll breach settlement. What exists today is the free CyberScout credit monitoring offered in the notice letters — reported as 12 months, and up to 24 months in some letters. Enroll using the code in your own letter.
Apple American Group Breach Timeline
- 1
April 8–9, 2026 — Servers Accessed
Per the company’s notice, an unknown actor accesses certain servers and accesses or acquires files.
- 2
April 9, 2026 — Activity Detected
The companies spot suspicious network activity, secure systems, start an investigation and notify federal law enforcement.
- 3
August 18, 2026 — Letters Go Out
Notice letters are mailed via Cyberscout and filed with state attorneys general, including Washington (20,653 residents) and Vermont.
- 4
Late August 2026 — Class Actions Filed
Suits are filed in the Northern District of Ohio; Hoodline reports Daniels (1:26-cv-02023) was filed August 24. Law360 reports a “slew” of suits on August 25.
- 5
September 2026 — At Least Eight Suits
Top Class Actions, citing Law360, counts at least eight proposed class actions, including Lema (1:26-cv-02013).
- 6
As of October 5, 2026 — No Settlement
The cases are at an early stage. No settlement, fund, administrator, claim form or deadline exists.
Three Things to Watch For
A breach that exposed Social Security numbers and bank details of restaurant workers, plus a lot of lawsuit headlines, is an easy setup for fraud:
“Claim your Applebee’s settlement” pages
There is no settlement and no claims portal. Law-firm “investigation” forms and lead-generation sites say “submit a claim”, but that signs you up with a firm, it does not file anything with a court. Never enter your Social Security number to “check eligibility.”
Fake payroll or HR messages
The stolen files came from employment records, so expect texts or emails posing as Applebee’s HR, payroll or direct-deposit staff asking you to “verify” bank details or log in. Contact your manager or HR through a channel you already know instead.
Calls asking for a fee or your full SSN
The real letter came from Cyberscout, P.O. Box 3826, Suwanee, GA, and offers free monitoring. A caller who wants a fee to enroll you, or your full Social Security number to “release” money, is not part of this. See our guide to Cyberscout breach letters.
Applebee’s Franchisee Lawsuit — Questions People Ask
Is this a lawsuit against Applebee’s itself?
The reported cases name Apple American Group LLC and Apple American Group II, LLC — the largest Applebee’s franchisee, part of Flynn Group — not the Applebee’s brand owner. The breach happened in the franchisee’s systems.
I ate at Applebee’s. Am I affected?
Probably not by this breach. The notice letter covers information people provided “during the course of your employment.” If you never worked for an Apple American Group restaurant and got no letter, this case is very likely not about you.
Is the letter from Apple American Group real?
The notice was filed with several state attorneys general, including Washington and California. The real letter is dated August 18, 2026 and sent c/o Cyberscout, P.O. Box 3826, Suwanee, GA 30024. Compare yours against the filed sample.
Is there a settlement or claim form?
No. As of October 5, 2026 the lawsuits are at an early stage, with no settlement, fund, administrator, claim form or deadline. If that changes, class members are notified directly. See open class action settlements for cases that are paying now.
How many people were affected?
No official nationwide total was found. State filings show 20,653 people in Washington, 16,241 in Massachusetts, 6,790 in New Hampshire, about 4,954 in Rhode Island and 2,992 in Vermont. ClaimDepot reports 282,573 in total; that figure is unverified.
Do I need to join or hire a lawyer?
No sign-up is needed to be in a class; if one is certified or a settlement is reached, you are included unless you opt out. Signing a law firm’s form is a retainer decision, not registration — read it before agreeing.
What did the lawsuits say about the delay?
The plaintiffs allege the companies found the breach on April 9, 2026 but did not send letters until August 18, 2026, about four months later, leaving people unable to protect themselves. The companies’ letter says there was no indication of identity theft or fraud; one plaintiff alleges fraudulent bank charges. Neither side’s account has been tested in court.
What should I do right now?
Enroll in the free monitoring using the code in your letter, freeze your credit at Equifax, Experian and TransUnion, and consider an IRS Identity Protection PIN. Watch bank statements and health insurance statements for activity you do not recognize. To see what past breach cases paid, try our data breach settlement calculator.
Separate from this case: were you injured in the last 2 years?
Class-action payouts are fixed amounts through an administrator. A personal injury claim is a different case — and often worth far more. Free estimate, no obligation.
Related Consumer Brand Lawsuits
Cyberscout Breach Letters
Who sends them and how to check a notice is real
Data Breach Settlement Calculator
What past breach settlements paid per person
Open Class Action Settlements
Settlements taking claims now, with deadlines
Settlement Payout Calculator
Estimate a per-person share from fund size and claims