
Apple American Group LLC, a major Applebee’s franchise operator in the United States, has disclosed a data breach incident.
The event has reportedly exposed sensitive personal information, including Social Security numbers, financial data, health records, and biometric information.
The total number of affected people remains unclear, but state filings indicate that at least 8,447 people were notified across Vermont, Rhode Island, and California. This includes 2,992 Vermont residents, approximately 4,954 Rhode Island residents, and at least 501 California residents.
A filing published by the Vermont Attorney General’s office on August 18, 2026, lists the compromised information as:
- Social Security numbers
- Government identification numbers
- Financial account codes
- Credit and debit card information
- Health records
- Biometric information
Apple American Group is a large restaurant franchise operator best known for running Applebee’s locations and is part of Flynn Group, one of the largest franchise operators in the United States. Its operations span multiple states.
The exposed data carries significant identity theft and fraud risks. Social Security and government ID numbers can be abused to open accounts or impersonate victims, while financial information may be used for unauthorized transactions or targeted scams.
Biometric information creates an additional concern because, unlike a password or payment card number, biometric characteristics cannot simply be replaced after they are compromised. The Vermont filing does not specify what type of biometric data was involved.
People who receive a breach notification from Apple American Group should review the notice carefully to determine what information belonging to them was affected.
Those whose Social Security numbers or government IDs were exposed should consider placing a credit freeze with Equifax, Experian, and TransUnion, monitor financial accounts for suspicious activity, and enable transaction alerts where possible. Affected individuals should also monitor bank and credit-card statements for unfamiliar activity, enable transaction alerts where available, and be cautious of emails, text messages, or phone calls that reference the breach. Those whose Social Security numbers were compromised can also consider obtaining an IRS Identity Protection PIN to reduce the risk of tax-return fraud.
Affected individuals should also watch for phishing emails, text messages, or calls referencing the breach, as stolen personal information can make scams more convincing.







Leave a Reply