The same April 2026 data breach that hit Applebee’s and IHOP employees has now also been confirmed at the Flynn Group entity that operates Panera Bread. Given Flynn Group’s shared corporate systems, employees of its Taco Bell, Arby’s, Wendy’s, and Planet Fitness operations should watch for a similar notice.
Flynn Group is one of the largest franchise operators in the United States, running roughly 2,600 locations across Applebee’s, IHOP, Pizza Hut, Taco Bell, Arby’s, Wendy’s, Panera Bread, and Planet Fitness. Flynn Group operates these brands through separate corporate entities, including Apple American Group LLC (Applebee’s and IHOP), HUT American Group LLC (Pizza Hut), Pan American Group LLC (Panera Bread), Bell American Group LLC (Taco Bell), RB American Group LLC (Arby’s), Wend American Group LLC (Wendy’s), and Flynn Fitness Group LLC (Planet Fitness). Several of these entities have now confirmed data breaches involving current and former employees.
Source: Flynn Group corporate website (flynn.com); California Attorney General data-breach notification list.
What’s Confirmed So Far
Two Flynn Group entities have filed matching breach notices with the California Attorney General, both describing the identical intrusion window and both sent from the same Independence, Ohio corporate address and phone number, a strong indication these were part of a single incident affecting Flynn Group’s shared back-office systems.
- Apple American Group LLC and Apple American Group II, LLC (Applebee’s and IHOP) — confirmed an intrusion between April 8 and April 9, 2026, and began notifying employees on August 18, 2026. Emery | Reddy has published a full write-up on this breach separately.
- Pan American Group LLC (Panera Bread) — confirmed the same April 8-9, 2026 intrusion window in a notice filed with the California Attorney General on August 24, 2026. Like Apple American Group’s notice, the letter states the exposed information is data “provided to us during the course of your employment,” meaning this is an employee data breach, not a customer or diner data breach.
- HUT American Group LLC (Pizza Hut) — separately confirmed a breach reported to the Texas Attorney General on August 21, 2026, from the same Independence, Ohio address, involving a notably broad set of exposed data including Social Security numbers, driver’s license numbers, financial account information, and medical information. The Texas filing does not disclose a specific intrusion date, so whether this is the same April incident or a related but separate event has not been confirmed. Emery | Reddy has published a full write-up on this breach separately.
Taco Bell, Arby’s, Wendy’s, and Planet Fitness: Not Yet Independently Confirmed
As of this posting, Emery | Reddy has not located a breach notice for Bell American Group LLC (Taco Bell), RB American Group LLC (Arby’s), Wend American Group LLC (Wendy’s), or Flynn Fitness Group LLC (Planet Fitness) in either the California Attorney General’s breach notification list or the Texas Attorney General’s data security breach report list, the two regulator databases where the other Flynn Group entities’ notices appeared. That does not mean these locations were not affected. Public filing is only required once a state’s reporting threshold is met, and notices to individuals can go out before, or without, a public regulator filing ever being required. Given that three other Flynn Group entities sharing the same corporate address have now confirmed breaches, current and former employees of Flynn Group’s Taco Bell, Arby’s, Wendy’s, and Planet Fitness locations should watch for a similar notice in the mail.
This Is Not the Earlier Panera Customer Data Breach
This is a different, more recent incident than the widely reported Panera, LLC data breaches Emery | Reddy has covered separately, including the 2024 Panera employee Social Security number breach and the early-2026 breach affecting an estimated 5.1 million Panera customer accounts tied to the ShinyHunters extortion group. Those incidents involved Panera, LLC, the corporate brand owner. This breach involves Pan American Group LLC, a Flynn Group franchisee that operates Panera Bread bakery-cafe locations, and affects employment data, not customer accounts. If you received a notice specifically from Pan American Group LLC referencing an April 2026 intrusion, this is the incident that applies to you; if your notice came from Panera, LLC regarding a different date, a separate case may apply, and you should keep both notices for your records.
What Information Was Exposed?
The version of Pan American Group’s notice letter posted to the California Attorney General’s website leaves the list of exposed data categories blank, the same placeholder pattern seen in Apple American Group’s posted sample. The letter confirms only that the exposed information is data employees provided to the company during their employment. Pan American Group has not made the specific data categories, such as Social Security numbers, dates of birth, or payroll information, publicly available at this time.
How Many People Are Affected?
None of the entities involved have disclosed a national total. Apple American Group’s posted notice confirms 4,954 affected Rhode Island residents; Pan American Group’s posted notice includes the same Rhode Island-specific disclosure paragraph but the actual figure was left blank in the version posted publicly. Flynn Group operates thousands of locations nationwide, so the full number of employees affected across all confirmed and suspected entities is likely far larger than any single state figure disclosed so far.
What Is Flynn Group Offering Affected Employees?
Both Apple American Group and Pan American Group are offering twelve months of complimentary credit monitoring and identity theft protection services through CyberScout, a TransUnion company. Affected individuals who want to enroll must do so within 90 days of the date on their notice letter by visiting bfs.cyberscout.com/activate and entering the unique code included in their letter. Questions can be directed to the dedicated assistance line included in the notice, or to the shared legal department at 216-525-2775.
Your Information Is at Risk
Employment records typically include Social Security numbers, dates of birth, and other sensitive personal details used for payroll and tax purposes. Even though the exposed data categories have not been itemized in the public notices, that combination of information is commonly used to open new credit, file a fraudulent tax return, or commit other forms of identity theft. Current and former employees of any Flynn Group brand should watch their financial accounts and credit reports closely and keep a copy of any notice letter they receive.
Do You Have Legal Options?
Employers have a legal duty to safeguard the personal information their employees provide to them. Current and former employees affected by these breaches may have rights and remedies under California and other state law, including claims tied to the length of time it took to notify affected individuals.
If you are a current or former employee of an Applebee’s, IHOP, Pizza Hut, Taco Bell, Arby’s, Wendy’s, Panera Bread, or Planet Fitness location and believe your information was affected, contact the Data Breach Attorneys at Emery | Reddy for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
FAQ
Which brands are involved in this breach?
Flynn Group operates Applebee’s, IHOP, Pizza Hut, Taco Bell, Arby’s, Wendy’s, Panera Bread, and Planet Fitness through separate corporate entities. Confirmed breaches have been reported for the entities operating Applebee’s/IHOP (Apple American Group), Pizza Hut (HUT American Group), and Panera Bread (Pan American Group). No public breach notice has yet been located for the entities operating Taco Bell, Arby’s, Wendy’s, or Planet Fitness, though those entities share the same corporate address as the confirmed ones.
I worked at Taco Bell, Arby’s, Wendy’s, or Planet Fitness. Am I affected?
That has not been independently confirmed as of this posting. No breach notice for Bell American Group (Taco Bell), RB American Group (Arby’s), Wend American Group (Wendy’s), or Flynn Fitness Group (Planet Fitness) has appeared in the California or Texas Attorney General breach databases. If you received a notice letter from any of these companies, or believe your information may have been affected, contact Emery | Reddy so we can track your case as this situation develops.
Is this the same as the Panera customer data breach I heard about?
No. This is a separate, more recent incident. This breach involves Pan American Group LLC, a Flynn Group franchisee, and affects employee data from an April 2026 intrusion. The earlier, widely reported Panera breaches involved Panera, LLC, the corporate brand owner, and affected customer accounts. If you’re not sure which notice applies to you, keep both letters and contact our office so we can help sort out which case covers you.
What information was exposed?
The posted sample notices for Apple American Group and Pan American Group both state only that the exposed information is data employees provided during their employment, without itemizing specific categories like Social Security numbers or dates of birth. HUT American Group’s separate Texas filing did itemize a broad set of categories, including Social Security numbers, driver’s license numbers, financial information, and medical information; see our separate post on that breach for details.
Why did it take so long to notify employees?
Apple American Group identified the intrusion in April 2026 but did not begin sending notice letters until August 2026, a gap of more than four months. Neither Apple American Group nor Pan American Group has publicly explained the reason for that gap.
Do I have a legal claim?
Employers are required by law to protect the personal information their employees provide to them, and a lengthy delay in notification can be relevant to that obligation. If you are a current or former employee of any Flynn Group brand and believe your information was affected, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.