Apple American Group Data Breach Lawsuit, Were You Affected? — Daniels v. Apple American Group, No. 1:26-cv-02023
If you got a letter this year saying your Social Security number sat exposed for months, you weren’t imagining how bad that felt. Apple American Group LLC, No. 1:26-cv-02023, and Apple American Group II LLC now face a wave of putative class actions over a data breach the companies allegedly sat on for four months before telling anyone.
Apple American Group Data Breach Lawsuit — Key Facts
| Field | Detail |
| Lawsuit Filed | August 24, 2026 (Daniels case). Lema case filing date: UNVERIFIED — docket entry not independently located |
| Defendant | Apple American Group, LLC and Apple American Group II, LLC |
| Alleged Harm | Unauthorized access to employee data (Social Security numbers, bank account details, health records, biometric data) between April 8-9, 2026; workers not notified until August 18, 2026 |
| Law Alleged | Ohio Rev. Code § 1349.19 (Ohio data breach notification statute); common-law negligence |
| Who Is Affected | Current and former Apple American Group employees — not Applebee’s/IHOP customers |
| Court & Case Number | U.S. District Court, N.D. Ohio — Daniels: No. 1:26-cv-02023; Lema: No. 1:26-cv-02013 |
| Current Stage | Complaints filed; no class certified yet |
| Lead Plaintiff Deadline | N/A — not a securities case |
| Settlement Status | No settlement. Active litigation only |
| Last Updated | September 18, 2026 |
Who Is Apple American Group and Why Are They Being Sued for a Data Breach?
Apple American Group is the largest Applebee’s franchisee in the country, running more than 460 restaurants — 35 of them in Ohio — and employing roughly 26,500 people. It’s owned by Flynn Restaurant Group, which also runs Pizza Hut, Taco Bell, Arby’s, Wendy’s, Panera, and Planet Fitness locations nationwide. Because Flynn’s HR and IT functions for the Applebee’s network run through a support center in Independence, Ohio, the lawsuits landed in Cleveland federal court even though Flynn’s headquarters sit in California.
That’s exactly the kind of employer holding the data that makes this breach so consequential. This wasn’t customer loyalty-card information — it was the personnel files of tens of thousands of servers, cooks, and managers.

What Did Apple American Group Do to Its Employees Between April and August 2026?
An unknown actor accessed company servers between April 8 and April 9, 2026, and pulled files containing employees’ Social Security numbers, bank account details, and health information. Apple American Group didn’t start mailing notice letters until August 18 — roughly four months later. Ohio Revised Code § 1349.19 requires businesses to notify affected residents “without unreasonable delay,” and courts have generally treated 45 days as the outer edge of reasonable. Four months is nearly triple that.
State filings confirm the exposure ran well beyond Ohio. Massachusetts counted 16,241 affected residents. Washington counted 20,653, and its filing listed driver’s license numbers, passport numbers, and biometric data among the exposed categories. Rhode Island, Vermont, and California each reported thousands more. A confirmed nationwide total hasn’t been made public — UNVERIFIED, no consolidated figure has surfaced in court filings so far.
Here’s the detail most coverage of this case has missed: Ohio Revised Code Chapter 1354 gives Ohio-headquartered companies an affirmative defense against exactly this kind of negligence claim — but only if the company can show it maintained a written cybersecurity program matching a recognized national framework. Whether Apple American Group had one in place before April 2026 is likely to become a central fight in this litigation, and it’s the kind of detail plaintiffs’ lawyers will be digging into before anyone talks settlement.
One employee’s account cuts against the company’s own paperwork. Jesse Lema, a former Walpole, Massachusetts server, says she’s been hit with a spike in spam calls and found fraudulent charges on her bank account since the breach was disclosed — even as the companies’ own filings indicated no identity theft or fraud had occurred. If a judge finds that gap significant, it could shape how the rest of the case unfolds.
Are You Part of the Apple American Group Data Breach Lawsuit?
Here’s exactly how to know if this case includes you.
You’re likely covered if any of the following applies:
- You worked for Apple American Group or Apple American Group II — at an Applebee’s or IHOP location — at any point before April 2026
- A notice letter dated on or after August 18, 2026, arrived from Apple American Group about a data breach
- Your Social Security number, bank details, health information, or biometric data was on file with the company as an employee, not a customer
You do not qualify if:
- You only dined at an Applebee’s or IHOP and never worked there — this breach involved employee records, not diner data
- You were never issued a state attorney general breach notice or a company letter about this specific incident
Apple American Group Employees Outside Ohio — Are You Still Covered?
Yes. This is a nationwide putative class action, not one limited to Ohio residents. Plaintiffs named in the various suits live in Florida, Massachusetts, Georgia, New York, Rhode Island, California, Pennsylvania, Vermont, and Washington, among other states. Coverage tracks where you worked and whether your data was compromised — not where the lawsuit happens to be filed.
That four-month wait is the whole ballgame here — if the court agrees it was unreasonable, everything else in this case gets easier for the people who received that letter.
Not sure if you qualify for the Apple American Group data breach lawsuit? A free consultation with a data privacy attorney can help you understand your options before evidence and deadlines start slipping away.
What Are Apple American Group Employees Asking the Court to Award?
There’s no money on the table yet, and there’s no claim form to fill out. These are proposed class actions, not a settlement — that distinction matters, because sites that talk about “your payout” at this stage are getting ahead of the facts.
Plaintiffs are asking the court to certify a class and to award damages for the costs of responding to the breach: credit monitoring, time spent freezing accounts, and, for people like Lema, actual fraud losses already incurred. They’re also asking for injunctive relief — a court order requiring Apple American Group to overhaul how it protects employee data going forward.
What Could Apple American Group Employees Receive If This Settles?
It’s impossible to predict a number this early. Outcomes in data breach class actions depend on how many current and former employees join, what the evidence shows about the company’s security practices, and how settlement talks eventually shake out. Talk to a class action lawsuit attorney if you want a realistic read on your specific situation rather than a guess pulled from a different case entirely.
What Should Apple American Group Employees Do Right Now?
- Don’t panic if you haven’t gotten a letter yet — notice letters have gone out in waves since August 18, and more may follow as the litigation surfaces additional affected states
- Save every piece of paper tied to this: the notice letter itself, any bank fraud alerts, and account statements showing suspicious activity
- If you’ve noticed spam calls, unfamiliar charges, or credit inquiries you didn’t make, document what to do if you’re a victim of identity theft — the same steps apply whether the exposed data came from a medical provider or an employer
- Enroll in the credit monitoring Apple American Group is offering — reporting describes offers ranging from one year to as long as 24 months of CyberScout identity protection, so check your specific letter for the exact term, and pair it with these steps to prevent identity theft while your data is circulating
- Watch the court’s docket for class certification and notice deadlines — this is early-stage litigation, and the timeline will move as motions get filed
- If your losses are significant, ask an attorney whether filing your own individual claim makes more sense than waiting on the class
Apple American Group Data Breach Lawsuit — Full Timeline
| Milestone | Date |
| Unauthorized access to company servers | April 8-9, 2026 |
| Breach reported to California, Massachusetts, New Hampshire, and Vermont AGs | August 18, 2026 |
| Notice letters mailed to affected employees | Beginning August 18, 2026 |
| Daniels complaint filed | August 24, 2026 |
| Lema complaint filed | UNVERIFIED — exact date not independently confirmed |
| Next scheduled hearing | UNVERIFIED — no hearing date publicly docketed as of this writing |
| Expected resolution | UNVERIFIED — no timeline has been set |
Apple American Group Data Breach — Frequently Asked Questions, No. 1:26-cv-02023
Is there a class action lawsuit against Apple American Group for the data breach right now?
Yes. At least eight to ten proposed class actions are pending in the U.S. District Court for the Northern District of Ohio, including Daniels v. Apple American Group, LLC, No. 1:26-cv-02023, and Lema v. Apple American Group LLC, No. 1:26-cv-02013. No class has been certified yet.
Do I need to do anything right now to be part of the Apple American Group lawsuit?
No. If you received a breach notice letter, your information is likely already in the company’s records that would define any future class. You don’t need to file anything to preserve your place — but saving your documentation now still matters.
When will the Apple American Group data breach case settle?
There’s no timeline. The case is still in its early pleading stage, and companies facing this kind of exposure often litigate for a year or more before any settlement talks begin.
Can I file my own lawsuit against Apple American Group instead of joining the class?
Yes, particularly if you’ve suffered documented fraud losses like Jesse Lema has described. An individual data breach compensation claim can sometimes recover more than a class share, though it also means covering your own legal costs unless you find a contingency-fee attorney.
How will I find out if the Apple American Group lawsuit settles?
Watch for a class notice mailed to the address on file with Apple American Group, or check the Northern District of Ohio’s PACER docket for either case number listed above.
What does the affirmative defense under Ohio Revised Code Chapter 1354 mean for the Apple American Group case?
It lets an Ohio-based company avoid liability on negligence claims if it can prove it had a written cybersecurity program matching a recognized framework before the breach. Whether Apple American Group qualifies is unresolved and could shape how far this case goes.
What specific law does Apple American Group allegedly violate?
The suits point to Ohio Revised Code § 1349.19, which requires notifying affected residents without unreasonable delay, plus common-law negligence claims over how the data was secured in the first place.
How much could Apple American Group employees get if this case settles?
Nobody knows yet. There’s no claim form, no settlement fund, and no dollar figure to point to. A data breach compensation lawyer can walk you through what similar cases have produced, but treat any number you see elsewhere as a guess.
Sources Used in This Apple American Group Data Breach Article
- Court Docket — Daniels v. Apple American Group, LLC et al., No. 1:26-cv-02023, N.D. Ohio, filed August 24, 2026: https://dockets.justia.com/docket/ohio/ohndce/1:2026cv02023/330433
- Ohio Revised Code § 1349.19 (data breach notification statute): https://codes.ohio.gov/ohio-revised-code/section-1349.19
- Massachusetts Attorney General — Apple American Group breach notification filing: https://www.mass.gov/doc/2026-1383-apple-american-group-llc-and-apple-american-group-ii-llc/download
- Washington State Office of the Attorney General — Data Breach Notifications: https://www.atg.wa.gov/data-breach-notifications
- Law360 Employment Authority — “Applebee’s Franchisee Faces Slew Of Data Breach Suits”: https://www.law360.com/employment-authority/other/articles/2517605/applebee-s-franchisee-faces-slew-of-data-breach-suits
Researched and written by Israr Ahmad, legal content researcher and founder of AllAboutLawyer.com. All facts verified against the Northern District of Ohio court docket and Ohio Revised Code § 1349.19 on September 18, 2026. Last Updated: September 18, 2026.
This article is for informational purposes only and does not constitute legal advice. Laws vary by state and individual circumstances differ. For advice about your specific situation, consult a qualified attorney.
About the Author
Israr Ahmad is a legal content researcher with 4+ years of experience covering class action settlements and consumer rights cases. He has researched and published coverage of 2,500+ settlements using verified court records, settlement administrator filings, and government sources. Learn more about Israr.
