
The company behind the country's largest chain of Applebee's restaurants is facing ten federal lawsuits after hackers broke into its systems and stole troves of employee data, including Social Security numbers, bank account details and health information, then waited months before telling workers what happened. Plaintiffs say the delay left thousands of current and former employees exposed to identity theft with no warning.
The lawsuits, filed in federal court in Cleveland and seeking class-action status, name Apple American Group LLC and Apple American Group II LLC as defendants, according to Cleveland.com. One of those cases, filed August 24 by lead plaintiff Shilo Daniels, was docketed in the U.S. District Court for the Northern District of Ohio under case number 1:26-cv-02023, per Justia court records. Plaintiffs in the various suits hail from Florida, Massachusetts, Georgia, New York, Rhode Island, California and Pennsylvania, Cleveland.com reports.
Apple American Group is the largest Applebee's franchisee in the country, operating more than 460 locations, including 35 in Ohio, and employing roughly 26,500 people according to the company's own website. It is owned by Flynn Restaurant Group, which is headquartered in California but runs its central Support Center at 6200 Oak Tree Boulevard in Independence, Ohio — a facility housing over 400 staff that handles administrative, HR, IT and operational functions for the franchise network, according to Flynn Group. That Ohio hub is why the litigation landed in Cleveland federal court even though Flynn's corporate headquarters sits on the West Coast.
A Four-Month Wait Before Workers Learned the Truth
Regulatory filings show unauthorized actors accessed company servers between April 8 and April 9, but the lawsuits allege the company already knew about the breach that month and still waited until earlier this month to notify many affected people, per the same Cleveland.com report. State breach notifications filed with attorneys general in Vermont, California and Massachusetts confirmed the timeline, and separate filings reviewed by Mass.gov put the gap between intrusion and notification at roughly four months.
The scale of what was exposed varies by state disclosure. The company reported that 16,241 Massachusetts residents and 2,992 Vermont residents were affected, according to Cleveland.com's review of the filings. A separate breach notification submitted to the Washington State Office of the Attorney General put the number of affected Washington residents at 20,653 and listed driver's license numbers, full dates of birth, military IDs, passport numbers, biometric data and account login credentials among the compromised categories, in addition to the Social Security numbers, bank numbers and health information cited in the Ohio suits.
A Server's Bank Account Hit With Fraud
Among the plaintiffs is Jesse Lema of East Providence, Rhode Island, who worked as a server at an Applebee's in Walpole, Massachusetts, from 2016 to 2019. Lema says she has received a spike in spam and scam calls since the breach was disclosed and later found fraudulent charges on her bank account, according to Cleveland.com's reporting. The lawsuits argue the companies indicated identity theft or fraud had not occurred in their filings, even as plaintiffs like Lema describe experiencing exactly that.
The suits allege Apple American Group LLC and Apple American Group II LLC failed to safeguard employee data and are asking a judge to certify a class that could include a large number of affected people in any eventual judgment or settlement. In response, the companies say they have offered one year of free credit monitoring and identity theft protection to those affected, though separate breach notification letters reviewed by Scott Hirsch Law Group indicate the company offered CyberScout monitoring and identity theft protection services lasting 12 to 24 months. The companies have also said they have changed the way they safeguard employee information going forward, per Cleveland.com.
Legal Exposure Under Ohio's Breach Notification Law
Ohio Revised Code Section 1349.19 requires businesses to notify affected state residents of a data breach as quickly as possible and no later than 45 days after discovery, with potential statutory penalties reaching $10,000 per day for noncompliance, according to the Ohio Revised Code. Whether the four-month gap described in the lawsuits runs afoul of that timeline is likely to be a central question in the litigation.
Ohio law may also hand the company a defense. Ohio Revised Code Chapter 1354 gives Ohio-headquartered businesses an affirmative defense against tort claims alleging inadequate security controls, provided the company maintains a written cybersecurity program aligned with recognized national frameworks. The statute was enacted in 2018 specifically to incentivize companies to adopt voluntary cybersecurity standards.
The Cleveland filings are part of a broader wave of legal scrutiny. Multiple national consumer protection firms — including Edelson Lechtzin LLP, Federman & Sherwood, and Migliaccio & Rathod LLP — launched class-action investigations into the breach following Apple American Group's August 18 disclosures, according to a notice distributed via PR Newswire. Data breach litigation has become increasingly costly nationally: IBM's 2026 Cost of a Data Breach Report found the average U.S. breach now costs a record $11.5 million, driven largely by class-action suits and multi-state compliance burdens, per an analysis from Baker Donelson.
A Sprawling Franchise Empire
Flynn Restaurant Group's footprint extends well beyond Applebee's. The company, founded in 1999 by Greg Flynn with eight Applebee's locations, has grown into what its own website describes as the largest franchise operator in the world. Its holdings include 1,200 Pizza Hut locations, at least 315 Taco Bells, 360 Arby's restaurants, 315 Wendy's locations, 150 Panera Bread restaurants and 140 Planet Fitness gyms, according to figures cited by Cleveland.com.
The company's rapid expansion continues even as the litigation unfolds. Hoodline previously reported on a Flynn-run Applebee's opening on Stephanie Street in June, part of the same franchise network now facing scrutiny over how it handled its workers' personal information. Cleveland.com's Adam Ferrise, who covers federal courts for the outlet and has worked there since 2013, first reported on the lawsuits.









-4.webp?w=1000&h=1000&fit=crop&crop:edges)