Wend American Group Data Breach Lawsuit Investigation
Received a September 2026 breach notice from Wend American Group?
Dapeer Law, P.A. is investigating a potential class action against Wend American Group LLC, an Ohio-based restaurant operating company that runs Wendy's locations across the United States, on behalf of individuals whose Social Security numbers, driver's license numbers, payment card details, financial account information, and medical information may have been exposed in the cybersecurity incident disclosed in the company's September 1, 2026 notice letters.
Who may qualify
You may be eligible to participate in a class action if any of the following applies:
- You received a data breach notification letter from Wend American Group dated September 2026.
- Your letter offered enrollment in twenty-four months of complimentary credit monitoring and identity theft protection through TransUnion, activated at the CyberScout portal with the unique code printed in your notice.
- You had personal, financial, or medical information held by Wend American Group, including information collected in the course of employment, benefits enrollment, or a payment transaction.
- No proof of harm required to consult with counsel. You do not need to have already suffered identity theft to explore your legal options.
- Excluded: individuals who did not receive a breach notice and whose information was not involved in the incident.
Not sure if you qualify?
Send us your notice, we'll confirm your eligibility at no cost.
What happened
According to the notice filed with the Massachusetts Attorney General, Wend American Group LLC identified an event that may have affected the privacy of certain information held on its network. The company states that it quickly confirmed the security of its network and began an investigation. The notice letter does not state when the unauthorized activity began, when it ended, or when the company first detected it, and it does not describe the type of incident involved. The Massachusetts filing carries the reference number 2026-1475 and reports that four Massachusetts residents were affected, which indicates the nationwide population is larger but has not been disclosed.
Wend American Group began notifying affected individuals with letters dated September 1, 2026. The regulator filing lists the categories of personal information potentially involved as Social Security numbers, driver's license numbers, credit and debit card numbers, financial account information, and medical information. The company says it has implemented additional cybersecurity measures and is reviewing its existing security policies. It is offering twenty-four months of complimentary credit monitoring and identity theft protection through TransUnion, and recipients must activate the service at bfs.cyberscout.com/activate using the unique code in their letter within ninety days of receipt. The letter states there was no indication of identity theft or fraud at the time it was sent, which describes the company's knowledge as of that date and does not establish that the information is safe.
This combination of data is unusually broad. A Social Security number, a driver's license number, and a financial account number cannot be reissued the way a payment card can, and together they support new account fraud, tax refund fraud, and identity assumption for years after a breach. Medical information adds separate exposure to medical identity theft and fraudulent insurance claims. Dapeer Law is evaluating whether the safeguards protecting this information were reasonable for a company holding Social Security numbers and medical records, whether the affected data was encrypted, how long the intrusion went undetected, and whether the notice provided enough detail for recipients to protect themselves.
What to do if you received a letter
Keep your notice letter
Do not discard it. Your letter contains the unique activation code for the TransUnion monitoring, the ninety day activation window, and the description of which categories of information were involved for you specifically, all of which is important evidence if you decide to participate in a lawsuit.
Enroll in the free 24-month credit monitoring
Activate the twenty-four months of credit monitoring and identity theft protection through TransUnion at bfs.cyberscout.com/activate, using the unique code printed in your letter. The notice states you must enroll within ninety days of receiving it. Accepting this benefit does not waive your right to pursue legal action.
Place a fraud alert or credit freeze
Contact Equifax, Experian, and TransUnion to place a fraud alert or freeze on your file. Request a free weekly credit report from AnnualCreditReport.com, and use the FTC's IdentityTheft.gov recovery guide. Because the notice lists medical information and payment card data alongside Social Security numbers, also review Explanation of Benefits statements from your health plan for services you did not receive, check card and bank statements line by line, and consider requesting an IRS Identity Protection PIN before the next filing season.
Speak with a data breach attorney
Consultations with Dapeer Law are free and confidential. We will review your notice, explain your options under state breach notification and privacy laws, and advise whether you may be eligible to join a class action.
Submit your notice for a free review
Two minutes online. A licensed attorney reviews every submission.
Breach timeline
Compensation you may be entitled to
Out-of-pocket expenses
Credit freezes, identity restoration services, and other costs incurred responding to the breach.
Time spent monitoring
Hours spent reviewing accounts, disputing fraudulent charges, and dealing with identity theft issues.
Identity theft & fraud losses
Unreimbursed funds stolen from accounts, unauthorized credit lines, medical identity theft and fraudulent insurance claims, unauthorized card and bank account charges, or tax refund fraud tied to the breach.
Statutory damages
Certain state data breach and consumer protection statutes provide for fixed damages regardless of actual loss.
Injunctive relief
Court orders requiring Wend American Group to implement stronger data security practices going forward, including encryption of stored Social Security numbers, driver's license numbers, and medical records, tighter access controls and monitoring on systems holding this information, and retention limits so the records of former employees and past customers are not held longer than necessary.
Compensation categories depend on applicable state law, the types of data exposed, and documented losses. No recovery is guaranteed.
Common questions
I received a data breach letter from Wend American Group. What should I do? +
Keep the letter, then activate the twenty-four months of complimentary credit monitoring and identity theft protection through TransUnion at bfs.cyberscout.com/activate using the unique code in your notice. The notice gives you ninety days from receipt. Because Social Security numbers, driver's license numbers, payment card details, financial account information, and medical information are all listed, review your bank and card statements, request your free credit reports at AnnualCreditReport.com or 1-877-322-8228, consider a fraud alert or security freeze with Equifax, Experian, and TransUnion, and watch for Explanation of Benefits statements covering care you did not receive. Report suspected identity theft to law enforcement and to the FTC at IdentityTheft.gov, preserve all breach-related correspondence, and contact a data breach attorney to discuss your options.
Am I eligible to join a class action against Wend American Group? +
If your personal information was involved in the incident described in the September 1, 2026 Wend American Group notice, you may be eligible. Eligibility generally depends on your state of residence, which categories of information appear in your individual letter, and whether you experienced documented losses or spent time responding to the breach. Some state breach notification and privacy laws allow claims based on the exposure itself, without proof of financial loss. Contact us for an individual assessment.
How much money could I receive from a class action lawsuit? +
Data breach class action recoveries vary significantly. Settlements typically range from a few hundred dollars for basic out-of-pocket losses to several thousand dollars for documented identity theft, with class size, damages, and negotiation all affecting the final amount. No payout is guaranteed, and this investigation has not yet resulted in a settlement.
What personal information was exposed in the breach? +
The Massachusetts Attorney General filing lists Social Security numbers, driver's license numbers, credit and debit card numbers, financial account information, and medical information as the categories of personal information potentially involved. The letter itself describes the event only in general terms and does not itemize what was affected for each recipient, so check your own notice, which should identify the categories that applied to you.
Did Wend American Group offer free credit monitoring? +
Yes. Wend American Group is offering twenty-four months of complimentary credit monitoring and identity theft protection services through TransUnion at no cost. The service is activated at bfs.cyberscout.com/activate with the unique code printed in your letter, and the notice states you must enroll within ninety days of receiving it, which for letters dated September 1, 2026 falls around the end of November 2026. Enrolling does not waive your right to bring a claim.
How many people were affected by the Wend American Group breach? +
Wend American Group has not publicly disclosed a nationwide total. The Massachusetts Attorney General filing reports four Massachusetts residents as affected, which reflects only that state and indicates the full population is larger. This page will be updated if the company or a regulator discloses a complete figure.
Is there a deadline to take legal action? +
Yes. Statutes of limitations for data breach claims vary by state and legal theory, typically ranging from one to six years. Waiting can permanently bar your claim. Contact us as soon as possible for a free evaluation.
How do I get a copy of the official breach notice? +
A copy of the Wend American Group notice letter was filed with the Massachusetts Attorney General under reference number 2026-1475 and can be downloaded from that office's website using the link in the sources section of this page. If you cannot locate your letter or the filed notice, Dapeer Law can help you obtain a copy during a free consultation.
Sources & references
- Official breach notice filing · Massachusetts Attorney General, Wend American Group LLC Breach Notice 2026-1475 (PDF)
- Credit monitoring activation · TransUnion identity protection activation portal (bfs.cyberscout.com)
- Company · Wend American Group LLC (wendamerican.com)
- Credit bureau freezes · Equifax · Experian · TransUnion
- Free weekly credit reports · AnnualCreditReport.com
- Identity theft recovery guide · FTC IdentityTheft.gov
Don't let the deadline decide for you. Submit your claim today.
You only have a limited window to act. Our team will review your notice, explain your options, and tell you whether you may be eligible to recover compensation, at no cost to you.