Eight class action lawsuits have been filed against Apple American Group, the largest Applebee’s franchisee in the United States, following a data breach the company discovered on April 9, 2026. Two new complaints were filed September 17 in Ohio federal courts, as plaintiffs allege the operator handled private employee data carelessly and failed to protect personal information from unauthorized access.
Apple American Group LLC and Apple American Group II LLC operate hundreds of Applebee’s Dine Brands locations across the United States, making the entity the largest franchisee of the franchise brand. The company sent data breach notification letters to affected individuals around August 18, 2026, roughly four months after the breach was initially identified. Those notifications triggered a wave of class action litigation that has now reached at least eight separate complaints, according to TopClassActions.com.
Two New Suits Filed September 17 in Ohio Federal Courts
Plaintiff Jesse Lema, who worked as an Applebee’s server from 2016 to 2019, filed case number 1:26-cv-02013 in the Northern District of Ohio, Eastern Division. Lema is represented by Robinson Law Farm LLC and Israel David LLC. A separate complaint was filed the same day by plaintiff Shilo Daniels, represented by Shamis & Gentile P.A., under case number 1:26-cv-02023 in the same district.
Both actions are brought as class actions seeking to represent a broader group of individuals whose personal data was affected by the breach. The two September 17 filings bring the total number of class action suits against Apple American Group to at least eight.
Allegations: Unencrypted Data and Delayed Notification
The lawsuits allege negligence, breach of implied contract, and unjust enrichment. Plaintiffs contend that Apple American Group stored personal information in a form that was neither encrypted nor redacted, and that the company’s approach to data security was described as “careless” in court filings cited by TopClassActions.com.
The notification timeline is also cited in several complaints. Class action attorneys commonly point to the gap between a breach discovery date and the date notification letters reach affected individuals as a factor in assessing whether a company took prompt steps to limit harm. In this case, the gap between the April 9 discovery and the August 18 notifications was approximately four months.
Key Dates in the Apple American Group Data Breach
April 9, 2026: Data breach discovered by Apple American Group.
August 18, 2026: Breach notification letters sent to affected individuals.
September 17, 2026: Two new class action complaints filed in Northern District of Ohio federal courts, bringing total suits to at least eight.
Data Breach Litigation in the Franchise Sector
Data breach class actions targeting franchise operators have increased in frequency as states expand consumer data protection laws and as federal courts have become more receptive to standing claims in privacy cases. Individual franchisees, as employers and operators of point-of-sale systems, collect personal information from employees and in some cases customers, creating data security obligations under a growing body of state and federal law.
Legal scholars note that liability in such cases typically falls on the franchisee as the data controller rather than on the franchisor, unless the franchisor had control over the systems involved. The eight lawsuits against Apple American Group remain in the early stages of litigation, and no trial dates have been set.
This content is provided for informational purposes only and does not constitute legal, tax, financial, or professional advice. Laws and regulations vary by state and individual circumstances and may change over time. Readers should consult a qualified attorney, tax professional, or other licensed professional regarding their specific situation. Nothing herein creates an attorney-client relationship.











