Skip to content

Security1 publisher3 min readPublished

Applebee's Franchisee Breach: SSNs, IDs, Health Records, Biometrics, Counted Only By State AGs

Apple American Group's regulator filings put 8,447 notifications across three states and list a data inventory closer to a clinic's than a restaurant's. No company-wide total has been published.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • Apple American Group LLC, a major Applebee's franchise operator in the United States, disclosed a data breach incident.
  • The incident reportedly exposed sensitive personal information including Social Security numbers, financial data, health records and biometric information.
  • The total number of affected people remains unclear, but state filings indicate at least 8,447 people were notified across Vermont, Rhode Island and California.
  • The state filings break down as 2,992 Vermont residents, approximately 4,954 Rhode Island residents, and at least 501 California residents.
  • The three published state figures sum exactly to the reported total of 8,447, indicating the total is the sum of three states' notification counts rather than a company-wide figure.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Apple American Group LLC, a major operator of Applebee's restaurants in the United States, has disclosed a data breach that it says exposed Social Security numbers, financial data, health records and biometric information [1][2]. The number of people affected in total remains unclear; what exists in public is a set of state attorney general filings that, added together, account for at least 8,447 notified individuals [3].

The arithmetic is worth stating plainly because it is the only arithmetic available. According to the state filings described by CyberInsider, 2,992 Vermont residents, approximately 4,954 Rhode Island residents and at least 501 California residents were notified [4]. Those three numbers sum exactly to the 8,447 figure being reported [5], which means the headline count is not an estimate of the incident's size. It is the size of the reporting obligation in three states that happen to publish. Rhode Island alone accounts for roughly 59 percent of the disclosed total [6], not because the breach concentrated there but because Rhode Island posts what it receives.

The more instructive document is the inventory. A filing published by the Vermont Attorney General's office on August 18, 2026 lists the compromised categories as Social Security numbers, government identification numbers, financial account codes, credit and debit card information, health records and biometric information [7]. That is the data profile of an employer of scale, not of a table-service brand: tax and eligibility paperwork, payroll banking details, benefits administration, and whatever timekeeping or access control system was collecting biometrics. Apple American Group is part of Flynn Group, described as one of the largest franchise operators in the United States, with operations spanning multiple states [8]. Franchise operators of that size run HR stacks with the same regulated categories a hospital or a bank holds, and considerably less scrutiny attached to them.

The biometric line is the one that does not age out. Unlike a password or a card number, a biometric characteristic cannot simply be reissued after it is compromised [9], and the Vermont filing does not specify what type of biometric data was involved [10]. That combination, an irreversible identifier plus an unspecified format, is the worst version of a disclosure: enough to establish exposure, not enough to assess it.

For individuals, the guidance in the reporting is conventional and still correct. Anyone whose Social Security number or government ID was exposed should consider a credit freeze at Equifax, Experian and TransUnion, monitor accounts, and enable transaction alerts where available [11]; those with exposed Social Security numbers can also request an IRS Identity Protection PIN to reduce tax-return fraud risk [12]. Breach notices themselves are the raw material for phishing, and messages referencing this incident should be treated accordingly [13].

What to watch: whether Apple American Group or Flynn Group publishes a company-wide affected count, or whether the number continues to be assembled by outsiders from whichever states mandate publication. Watch for additional AG filings in states with lower or later thresholds, which would move the 8,447 figure without any new facts about the intrusion [3][5]. And watch the biometric detail specifically, because the type of biometric data, and whether it was stored as a template or as an image, determines whether this is a payroll incident or a permanent one [10].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories