← Apple American Group

2026 Apple American Group (Applebee’s franchisee) — network intrusion Apr 8–9; SSN/financial/health/biometrics; ≥8,447 notified

2026 8.4K records affected Share on X

Data compromised

Per Vermont AG filing categories and CyberInsider/DataBreaches summaries of notices: Social Security numbers, government ID numbers, financial account codes, credit/debit card information, health records, and biometric information — exact biometric type and full national census not published; ≥8,447 notified across VT (~2,992), RI (~4,954), and CA (≥501)

Technical writeup

Verified company/regulator notices via California AG sample and multi-state filings summarized by CyberInsider and DataBreaches.net — August 20, 2026 reporting. Apple American Group LLC and Apple American Group II, LLC (major Applebee’s franchise operator under Flynn Group) notified that suspicious network activity on April 9, 2026 led investigators to conclude data was accessed and exfiltrated between April 8 and April 9. Vermont AG materials list compromised categories including SSNs, government IDs, financial account codes, payment cards, health records, and biometric information. Aggregate notified count across Vermont (~2,992), Rhode Island (~4,954), and California (≥501) is at least 8,447; national total may be higher and was not fully published at indexing. recordsAffected 8447 = sum of cited state notification floors.

Root cause

Company-disclosed unauthorized network access and data exfiltration April 8–9, 2026 (Apple American Group / Apple American Group II); multi-state AG notifications August 2026

References