Apple American Group Data Breach Lawsuit Investigation

Active investigation · Free, confidential case review
Call (954) 799-5914
Data Breaches / Apple American Group
Active investigation Data breach · Restaurants Notices mailed Aug 18, 2026

Received an August 2026 breach notice from Apple American Group?

Dapeer Law, P.A. is investigating a potential class action against Apple American Group LLC and Apple American Group II, LLC, an Ohio-based operator of one of the largest casual dining franchise groups in the country, on behalf of current and former employees whose personal information may have been exposed in the April 2026 cyber incident disclosed in the company's August 2026 notice letters.

Submit your claim See what to do No fee unless we recover for you
Breach window
April 8 to 9, 2026
Unauthorized server access and file acquisition
Notification delay
About 4 months
Discovered April 9, 2026, notices dated August 18, 2026
Credit monitoring
12 months
Through CyberScout, a TransUnion company
Eligibility

Who may qualify

You may be eligible to participate in a class action if any of the following applies:

  • You received a data breach notification letter from Apple American Group dated August 2026.
  • Your letter offered enrollment in twelve months of complimentary credit monitoring and identity theft protection through CyberScout, a TransUnion company.
  • You had personal information held by Apple American Group in its capacity as your current or former employer, including information you provided during the course of your employment.
  • No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
  • Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.

Not sure if you qualify?

Send us your notice, we'll confirm your eligibility at no cost.

Check eligibility
Background

What happened

According to the notice letter filed with the California Attorney General, Apple American Group detected suspicious activity on its network on April 9, 2026 and moved to secure its systems. The company engaged third-party forensic specialists, and that investigation determined that an unknown actor accessed certain company servers between April 8, 2026 and April 9, 2026 and accessed or acquired certain files stored on those servers during that window. A subsequent review of the affected files determined that information belonging to current and former employees may have been present.

Apple American Group states that it completed its review and began notifying potentially affected individuals with letters dated August 18, 2026, roughly four months after the intrusion was discovered. The letter describes the information involved only as personal information provided during the course of employment, and does not itemize the specific data fields for each recipient. Employment records held by a large restaurant operator commonly include names, Social Security numbers, dates of birth, direct deposit and payroll details, and benefits enrollment information, so recipients should treat their information as potentially sensitive until their individual letter confirms otherwise. The company is offering twelve months of complimentary credit monitoring and identity theft protection services through CyberScout, a TransUnion company, and recipients must enroll within ninety days of the date on the letter.

Employment data carries a longer risk tail than a stolen payment card. A Social Security number, a date of birth, and a bank routing and account number used for direct deposit cannot be reissued the way a card can, and together they support tax refund fraud, fraudulent unemployment claims, new account fraud, and payroll redirection. Dapeer Law is evaluating whether the security controls protecting Apple American Group's servers were reasonable for an employer holding this volume of workforce data, whether the files taken were adequately protected, and whether the roughly four month gap between discovery and notification left employees exposed longer than necessary.

Unauthorized server access Employee personal information Files acquired by unknown actor California Attorney General filing Four month notification delay CyberScout monitoring offered
Action plan

What to do if you received a letter

1

Keep your notice letter

Do not discard it. Your letter contains the enrollment code for the CyberScout monitoring services, the ninety day enrollment deadline, and the description of what information was involved for you specifically, all of which is important evidence if you decide to participate in a lawsuit.

2

Enroll in the free 12-month CyberScout monitoring

Enroll in the twelve months of credit monitoring and identity theft protection through CyberScout, a TransUnion company, offered in your letter. Enrollment must be completed within ninety days of the date printed on the letter. Accepting this benefit does not waive your right to pursue legal action.

3

Place a fraud alert or credit freeze

Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because payroll and direct deposit information is commonly held in employment records, also review your bank account for unfamiliar changes to direct deposit instructions, watch for unemployment claims filed in your name, and consider requesting an IRS Identity Protection PIN before the next filing season.

4

Speak with a data breach attorney

Consultations with Dapeer Law are free and confidential. We will review your notice, explain your options under state breach notification and privacy laws, and advise whether you may be eligible to join a class action.

Submit your notice for a free review

Two minutes online. A licensed attorney reviews every submission.

Submit your claim
Timeline

Breach timeline

April 8 to 9, 2026 Passed
Unknown actor accesses Apple American Group servers and acquires files
April 9, 2026 Passed
Suspicious network activity detected, systems secured
April to August 2026 Passed
Third-party forensic investigation and review of affected files
Aug 18, 2026 Passed
Notice letters dated, sample notice filed with the California Attorney General
About Nov 16, 2026 Active
Approximate deadline to enroll in CyberScout monitoring, ninety days from the letter date
Pending Active
Potential class action filing
Statutes of limitations vary by state and legal theory, typically one to six years. Claims arising from employment records can also implicate state wage, payroll, and personnel record statutes with their own filing periods. Waiting can permanently bar your claim.
Possible recovery

Compensation you may be entitled to

Out-of-pocket expenses

Credit freezes, identity restoration services, and other costs incurred responding to the breach.

Time spent monitoring

Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.

Identity theft & fraud losses

Unreimbursed funds stolen from accounts, unauthorized credit lines, tax refund and unemployment benefits fraud, payroll and direct deposit redirection, or tax refund fraud tied to the breach.

Statutory damages

Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.

Injunctive relief

Court orders requiring Apple American Group to implement stronger data security practices going forward, including tighter access controls and monitoring on servers holding employee records, encryption of stored personnel data, and retention limits so former employees' information is not held longer than necessary.

Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.

FAQ

Common questions

I received a data breach letter from Apple American Group. What should I do? +

Keep the letter, then enroll in the twelve months of complimentary credit monitoring and identity theft protection through CyberScout using the code in your notice. Enrollment closes ninety days after the date on the letter. Because employment records commonly include Social Security numbers and direct deposit details, review your bank, credit card, and retirement accounts for unfamiliar activity, check your credit reports at AnnualCreditReport.com, and consider placing a fraud alert or security freeze with the three credit bureaus. Preserve all breach-related correspondence, and contact a data breach attorney to discuss your options.

Am I eligible to join a class action against Apple American Group? +

Current and former employees whose information was included in the August 18, 2026 notice may be eligible. Eligibility generally depends on your state of residence, the categories of information involved in your individual letter, and whether you experienced documented losses or spent time responding to the breach. Some state breach notification and privacy laws allow claims based on the exposure itself, without proof of financial loss.

How much money could I receive from a class action lawsuit? +

Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.

What personal information was exposed in the breach? +

The notice states only that information provided during the course of your employment may have been involved, and it does not itemize the specific data fields. Employment records held by a large restaurant operator commonly include names, Social Security numbers, dates of birth, direct deposit and payroll information, and benefits data. Because the public notice is not specific, check your own letter, which describes what was involved for you.

Did Apple American Group offer free credit monitoring? +

Yes. Apple American Group is offering twelve months of complimentary credit monitoring and identity theft protection services through CyberScout, a TransUnion company. The notice states that you must enroll within ninety days from the date of the letter, so for letters dated August 18, 2026 the deadline falls in mid-November 2026. Enrolling does not waive your right to bring a claim.

How many people were affected by the Apple American Group breach? +

Apple American Group has not publicly disclosed a nationwide total. The version of the notice filed publicly references approximately 4,954 residents of a single state as potentially impacted, which suggests the full population is larger, but no complete figure has been released. This page will be updated if the company or a regulator discloses revised numbers.

Is there a deadline to take legal action? +

Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.

How do I get a copy of the official breach notice? +

A copy of the Apple American Group notice of data event was filed with the California Attorney General and can be downloaded from that office's data breach notification page. If you cannot locate your letter or the filed notice, Dapeer Law can help you obtain a copy during a free consultation.

References

Sources & references

Attorney advertising. This page is provided for informational purposes only. It does not constitute legal advice or form an attorney-client relationship. Dapeer Law, P.A. is not affiliated with Apple American Group LLC and Apple American Group II, LLC, CyberScout, or any credit bureau. Prior results do not guarantee a similar outcome. All information regarding the data incident is drawn from the official notification filed with California Attorney General on August 18, 2026.
Free, confidential case review

Don't let the deadline decide for you. Submit your claim today.

You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.

Why Dapeer Law

Practice focusConsumer class actions
Licensed inFL · NY · NJ · IL
Case review fee$0
Response timeSame business day
Free case review
Confidential · 2 minutes
Submit claim →
Previous
Previous

Silver Summit Medical Data Breach Lawsuit Investigation

Next
Next

Greenwood County Hospital Data Breach Lawsuit Investigation