Shopping & subscriptions

Applebee’s account hacked? Here’s what to do

Move fast and in the right order: reclaim the account through Applebee’s’s official flow, kick the attacker out of every session, then close the door they came through — usually a password that leaked in a breach and was reused.

ByNikita Lushpanov· Chief Product Officer ·LinkedIn

The Applebee’s breach letters came from the company that runs the restaurants, not from Applebee’s

If a letter reached you in the second half of August 2026, it was sent by Apple American Group LLC, the largest Applebee’s franchisee in the country, and it is about staff records rather than anything you ordered. State filings from 18 August describe an intruder inside the company’s servers on 8 and 9 April 2026, and files taken during those two days: names, Social Security numbers, government identification numbers, financial account and card details, health records and biometric data. That is the shape of an employment file, not a receipt. No notice so far says diner payment data was involved, and there is no Applebee’s password of yours anywhere in this story. The part worth acting on is the Social Security number, because unlike a card it is never reissued.

The FTC’s official recovery plan for a stolen Social Security number

Breach notifications filed with state attorneys general from 18 August 2026, and reporting by Law360, DataBreaches.net and Cleveland.com between 20 and 28 August 2026.

Quick answer

If your Applebee’s account was hacked: start recovery at the official page (www.applebees.com/en/contact-us), change the password to a unique one, sign out all other sessions, and re-check the recovery email and phone on the account. Then find out how the attacker got in — check whether your password appears in known breach data — and turn on two-factor authentication so it can’t happen again.

Recover your Applebee’s account, step by step

These steps follow Applebee’s’s official process. Official links only: account recovery.

1

Freeze your credit file at Equifax, Experian and TransUnion. It is free, it is done online in a few minutes at each, and it blocks new accounts rather than reporting them afterwards. You can lift it temporarily whenever you actually apply for something.

2

Enrol in the monitoring using the code on the letter. These offers run on a clock measured from the date the letter was posted, so an envelope opened three months late may already be past its enrolment window, and there is no way to activate the cover without the code.

3

Request an Identity Protection PIN from the IRS. A Social Security number and a date of birth is the combination used to file a tax return in someone else’s name, refund fraud peaks early in the year, and the PIN makes a return without it impossible to file.

4

Pull your credit reports at annualcreditreport.com and read them line by line for accounts, addresses and enquiries you do not recognise. Free reports are available weekly, so it is worth doing again in a few months rather than once.

5

Treat every phone call about this as hostile until proven otherwise. A breach with published class actions gives callers a script, and a convincing one will already know where you worked. Nobody legitimate needs your Social Security number over the phone to activate monitoring you were sent a code for.

6

If something has already been opened or filed in your name, report it at identitytheft.gov before you start calling companies. It produces the affidavit and the recovery plan that banks, the IRS and collection agencies actually ask for, and having it first saves repeating the story to everyone separately.

What trips people up with Applebee’s

  • The unfamiliar sender is the most common reason people bin this letter as junk. Apple American Group is not a name you would have seen on a payslip if you thought of yourself as working for Applebee’s, and the envelope carries a claims administrator’s return address on top of that. Check it the safe way rather than by how it looks: the state attorney general breach lists are public, and your old employer’s HR line can confirm a mailing without you handing anything over.
  • Former staff are the ones this misses. The letter goes to the address the company had on file when you left, so if you worked a season in 2022 and have moved twice since, nothing will arrive and nobody will chase you. The files taken were employment records, which employers keep for years after someone leaves. If you were on the payroll at any point recently, act as though you are on the list instead of waiting for confirmation.
  • Biometric data is the entry in this notice that behaves differently from the rest. Restaurants use fingerprint or palm scans to clock people in and out, and a template like that cannot be reissued the way a card number or even a Social Security number can be reassigned in extreme cases. There is nothing an individual can do to rotate it, which is precisely why several of the complaints filed in Ohio and California lean on it, and why the legal side of this may run for years.
  • The health information in a restaurant breach is not hospital data. It is what an employer holds because it administers a health plan: enrolment forms, insurance identifiers, sometimes accommodation or leave paperwork. That still matters, because health plan identifiers are used for medical identity theft and those cases are far harder to unpick than a fraudulent credit card, but it is worth knowing what it means before assuming a doctor’s office was involved.
  • Credit monitoring is an alarm, not a lock. The 12 months on offer tells you after something has been opened in your name, which is useful but late. A credit freeze at all three bureaus is the thing that stops the account being opened in the first place, it is free by federal law, it takes about ten minutes per bureau online, and unlike the monitoring offer it does not quietly expire in a year.

Was Applebee’s hacked, or the company that runs the restaurants?

The second one. Almost every Applebee’s in the United States is run by a franchisee rather than by the brand, and the largest of them is Apple American Group LLC, which operates hundreds of restaurants across roughly 23 states out of Independence, Ohio, alongside a set of IHOPs, as part of Flynn Restaurant Group. That is the company that holds payroll paperwork, tax forms and benefits records for the people behind the counter. It found suspicious activity on its network on 9 April 2026 and its investigation concluded that an unauthorised actor had reached and copied certain files between 8 and 9 April. The letters went out in the second half of August, more than four months later, which is normal for a review of this size and is also why the news and the letter arrive at people in the wrong order.

The state-by-state filings are the only public measure of scale, and they are partial by design: a company files separately in each state where residents were affected, so what is visible is a floor rather than a total. Those filings account for roughly 16,000 people in Massachusetts, about 6,800 in New Hampshire, around 4,900 in Rhode Island and about 3,000 in Vermont, with smaller counts elsewhere; no national figure has been published. Law360 reported on 26 August that at least eight proposed class actions had already been filed in federal courts in California and Ohio, describing tens of thousands of employees and, unusually for a restaurant company, health information among the data taken. Apple American is offering 12 months of credit monitoring and identity theft protection through CyberScout, activated with the code printed on the letter.

It is also not the only letter of its kind this month. HUT American Group LLC, which runs Pizza Hut restaurants, began notifying people on 20 August and filed in Texas on 21 August. Bell American Group LLC, a Taco Bell operator based in Indianapolis, reported to Massachusetts regulators on 26 August and posted its letters the same day. Pan American Group LLC, on the Panera Bread side, filed in California on 24 August. All four are Flynn Restaurant Group companies, and the ones that gave dates all point at the same two days in April. None of them has formally said the incidents are the same incident, and reporting has been careful to leave that open, so the honest description is a single week of notifications across sister companies with a shared corporate address.

Got a "new login" alert from Applebee’s?

Treat it as real but verify it the safe way: never tap the link in the message itself (fake login alerts are a top phishing template for Applebee’s). Open the app or type the address yourself, check the active-sessions list in security settings, and if you see a device or location you don't recognize, sign it out and change your password immediately. If the alert was genuine, that password is burned — assume it's circulating and change it everywhere else you reused it.

Still logged in? Lock the account down now

If you can still get in, you're racing the attacker. In this order: change the password to a long, unique one; sign out all other sessions/devices (the setting exists in Applebee’s's security settings); confirm the recovery email and phone number are yours (attackers quietly add their own so they can "recover" the account later); remove unfamiliar linked apps or API access; and turn on two-factor authentication. Only then deal with anything the attacker posted, sent or bought.

The attacker spent, moved or stole orders, gift-card balance or loyalty rewards

Document everything first (screenshots of orders, trades or transfers, with dates), then report it through Applebee’s's official support flow — platforms restore fraudulent purchases and stolen orders, gift-card balance or loyalty rewards case-by-case, and a clean, dated report is what gets approved. If a card or bank account was charged, dispute the charges with the issuer as unauthorized. Change the password on the email account attached to Applebee’s too — if the attacker owns your inbox, they'll just take the account back.

Why this happened — and how to make sure it can’t again

About a third of account takeovers are credential stuffing: a password you used on Applebee’s (or the email behind it) leaked in some other company’s breach, and attackers replayed it here automatically. The FBI’s IC3 logged over 5,100 account-takeover complaints with $262M in losses in 2025 alone (IC3). Even when Applebee’s itself was never breached, your reused password from another site opens it.

So after recovery, check what’s already out there: our free scanner shows which known breaches and dark-web dumps include your email — and whether passwords were exposed with it.

Check my exposure — free →

After you recover: three doors to close

  1. Unique password + 2FA. A password manager plus app-based two-factor stops both stuffing and phishing replays.
  2. Reset everywhere you reused that password — email first (it’s the master key), then bank, then the rest.
  3. Shrink your public footprint. Attackers research targets on data-broker sites (your address, phone, relatives — enough to social-engineer support lines). Our free opt-out guide covers 190 of them, step by step.
Common questions

Hacked Applebee’s account, answered

How did my Applebee’s account get hacked?

The most common cause isn't a hack of Applebee’s itself — it's credential stuffing: a password you used on Applebee’s leaked from some other site's breach, and attackers tried it here automatically. Roughly a third of account takeovers happen this way, with phishing (fake Applebee’s login pages and alerts) close behind. That's why the first fix is a unique password, not just a new one.

Can I get my Applebee’s account back?

Usually yes. Use the official recovery flow (https://www.applebees.com/en/contact-us) — it can verify you even when the attacker changed the email and password. Be patient and respond quickly to follow-ups so the case stays open.

Should I just make a new Applebee’s account instead?

Not until you've tried recovery. The old account keeps your history and contacts — and while the attacker controls it, it will be used to scam people who trust you. Recover it, or at minimum report it as compromised so Applebee’s can lock it, before you start over.

The hacker placed orders or drained gift cards on my Applebee’s account — now what?

Report the orders as unauthorized through Applebee’s's support, dispute any card charges with your bank, and check saved addresses and payment methods for ones the attacker added. Loyalty points and gift-card balances are a favorite target because people don't watch them like a bank account — screenshot balances and include them in the report.

Was Applebee’s itself hacked in 2026?

No. The notices came from Apple American Group LLC, a franchisee that operates hundreds of Applebee’s restaurants and a number of IHOPs under Flynn Restaurant Group, and they describe an intrusion into that company’s own servers on 8 and 9 April 2026. The brand’s corporate systems are not what was named in any of the filings, which is also why the letter arrived from a company most people who worked there had never heard of.

I ate at Applebee’s this year. Is my card at risk?

Nothing published so far points that way. Every filing describes information collected from people during their employment, which is a different system from the tills and the payment terminals, and no notice has mentioned guest payment data. The routine advice still applies, in that reading your card statement costs nothing, but there is no reason here to cancel a card over a meal.

I stopped working there two years ago. Am I in this?

Possibly, and you may never be told. Employment records are kept long after someone leaves, and the notification is posted to whatever address the company last had for you. If you were on the payroll in recent years, the sensible reading is that you are in scope: freeze your credit, get an IRS Identity Protection PIN, and check whether your state attorney general publishes the breach filing, which will list who was notified.

Why does the letter mention medical and biometric information?

Because a large employer holds both. The health entry is health plan paperwork rather than clinical records, and the biometric entry is almost certainly the fingerprint or palm template used to clock in and out of shifts. Both are named in the complaints filed in California and Ohio, and the biometric part is the one with no personal remedy, since a fingerprint cannot be changed after it leaks.

There are class actions. Should I do anything about them?

Nothing urgent. At least eight proposed class actions were on file by 26 August, and cases at this stage take months to be consolidated before anyone is asked for anything. Keep the letter, keep a note of the date it arrived, and be sceptical of anyone contacting you first about joining a claim. Real settlements are announced through a court-approved administrator and never ask for a Social Security number by phone.

My friend at Taco Bell got a similar letter. Same thing?

Same corporate family and the same week. Bell American Group on the Taco Bell side, HUT American Group on the Pizza Hut side and Pan American Group on the Panera side all sent notifications in the second half of August 2026, and they are all Flynn Restaurant Group companies. Whether it was one intrusion or several has not been confirmed by any of them, though the dates given by those that gave dates line up.

How do I stop my Applebee’s account being hacked again?

Three things close most of the doors: a unique password (a manager makes this painless), app-based two-factor authentication, and shrinking your exposed footprint — checking your email against known breach databases and removing your personal data from data-broker sites that attackers use to research targets.