TechNewsReel
Live

Largest Applebee’s Franchisee Reports Employee Data Breach

Apple American Group detected unauthorized access to files containing Social Security numbers and biometric data.

TechNewsReel Newsroom · August 20, 2026

Apple American Group, the largest Applebee’s franchisee in the United States, has reported a data breach that potentially exposed the highly sensitive personal information of its employees. The security incident highlights the ongoing vulnerability of large-scale service operators to targeted network intrusions.

According to filings disclosed to the Vermont Attorney General on August 18, 2026, Apple American Group LLC and Apple American Group II, LLC detected suspicious network activity on April 9, 2026. An investigation determined that an unauthorized actor accessed company files over a brief window between April 8 and April 9, 2026. While the duration of the access was short, the nature of the data involved is extensive. The breach potentially exposed employee Social Security numbers, government ID numbers, financial account codes, credit and debit account information, health records, and biometric information. In Vermont alone, at least 2,992 residents were affected by the incident.

Corporate Footprint

Apple American Group LLC is a wholly owned subsidiary of Flynn Restaurant Group. Headquartered in Independence, Ohio, the company maintains a massive operational footprint, managing hundreds of Applebee’s locations across approximately 23 states. As the largest franchisee for the brand in the U.S., the company manages a vast workforce, making its internal employee databases a high-value target for unauthorized actors seeking permanent identifiers.

Risks of Permanent Data Loss

This breach is particularly severe due to the types of data potentially compromised. Unlike passwords or credit card numbers, which can be reset or canceled, Social Security numbers and biometric data are permanent identifiers. When these are paired with health records and financial account codes, the risk of sophisticated identity theft and long-term financial fraud increases significantly for the affected staff. The exposure of health data further complicates the breach, potentially violating employee privacy on a deeply personal level.

Looking Ahead

It remains to be seen how many employees across all 23 states were impacted beyond the initial figures reported in Vermont. The company has not yet detailed the specific security failures that allowed the unauthorized actor to access the files or whether the actor has been identified. Industry observers will be watching for further disclosures regarding the total number of affected individuals and any remedial measures the company is providing to protect employees from identity theft.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.