Skip to main content
Jump to a category page

Flynn Group runs Applebee’s, IHOP, Pizza Hut, Taco Bell, Arby’s, Wendy’s, Panera Bread, and Planet Fitness through separate corporate entities that share back-office systems. Four of those entities have now confirmed employee data breaches. Flynn Fitness Group, the entity behind its Planet Fitness clubs, has not yet filed a breach notice of its own, but the pattern is hard to ignore.

Flynn Group is one of the largest franchise operators in the country, running roughly 2,600 locations nationwide. It operates its different brands through separate corporate entities, including Apple American Group (Applebee’s and IHOP), HUT American Group (Pizza Hut), Pan American Group (Panera Bread), Bell American Group (Taco Bell), and Flynn Fitness Group (Planet Fitness). As of this writing, four of those entities, Apple American Group, HUT American Group, Pan American Group, and Bell American Group, have confirmed data breaches involving current and former employees. Emery | Reddy has published detailed write-ups on several of these confirmed breaches separately.

Why Planet Fitness Employees Should Pay Attention

No breach notice has yet been located for Flynn Fitness Group LLC, the entity that operates Flynn Group’s Planet Fitness locations, in the California Attorney General’s breach notification list, the Texas Attorney General’s data security breach report list, or the Massachusetts Office of Consumer Affairs and Business Regulation’s data breach notifications, the same regulator sources where the other four confirmed Flynn Group breaches have appeared. That does not mean Planet Fitness employees were not affected. Three of the four confirmed entities trace back to the same April 8-9, 2026 intrusion window in Flynn Group’s shared corporate systems, and public filing is only required once a state’s reporting threshold is met, meaning notices to individuals can go out before, or without, a public regulator filing ever being required.

If you are a current or former employee of a Flynn Group-operated Planet Fitness club, you may be affected by the same shared-systems incident even though no breach has been independently confirmed for Flynn Fitness Group specifically as of this writing.

What’s Already Confirmed at Sibling Flynn Group Brands

  • Apple American Group (Applebee’s/IHOP): confirmed an intrusion between April 8 and April 9, 2026, notice began August 18, 2026.
  • Pan American Group (Panera Bread): confirmed the same April 8-9, 2026 intrusion window, notice filed with California regulators August 24, 2026.
  • HUT American Group (Pizza Hut): confirmed a breach reported to Texas regulators August 21, 2026, with Social Security numbers, driver’s license numbers, financial account information, and medical information among the exposed categories.
  • Bell American Group (Taco Bell): confirmed a breach reported to Massachusetts regulators August 26, 2026, itemizing Social Security numbers, medical records, financial account information, driver’s license numbers, and credit or debit card numbers.

Arby’s (RB American Group) and Wendy’s (Wend American Group) remain unconfirmed alongside Planet Fitness, for the same reason: no independent regulator filing has surfaced yet for those entities either.

What Is Flynn Group Offering Affected Employees?

At the confirmed entities, Flynn Group has offered twelve months of complimentary credit monitoring and identity theft protection through Cyberscout, a TransUnion company, with a longer twenty-four month period offered to affected Bell American Group (Taco Bell) employees. Whether a similar offer would apply to Flynn Fitness Group employees, if a breach is confirmed there, is not yet known.

Do You Have Legal Options?

Employers have a legal duty to safeguard the personal information their employees provide to them. Current and former employees of any Flynn Group brand, including Planet Fitness, may have rights and remedies under applicable law if their information was involved in this incident.

If you are a current or former employee of a Flynn Group-operated Planet Fitness location and believe your information may have been affected, or if you receive a notice letter, contact the Data Breach Attorneys at Emery | Reddy for a Free Case Review.

Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Employers are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.

Frequently Asked Questions

Has a breach been confirmed at Planet Fitness locations run by Flynn Group?

Not independently, as of this writing. No breach notice for Flynn Fitness Group LLC has appeared in the California, Texas, or Massachusetts breach databases where four sibling Flynn Group entities have already confirmed breaches.

Why should I be concerned if nothing has been confirmed yet?

Four of Flynn Group’s eight brand entities have now confirmed employee data breaches, three of them tracing to the same shared-systems intrusion in April 2026. Given that pattern, current and former Planet Fitness employees at Flynn Group-operated clubs should watch closely for a notice letter.

I work at a Planet Fitness location. Is it definitely a Flynn Group club?

Not all Planet Fitness locations are operated by Flynn Group; Planet Fitness is a franchise brand with many different operators. This applies specifically to clubs operated by Flynn Fitness Group LLC. If you’re not sure who operates your location, your pay stub or employment paperwork should identify your employer of record.

What should I do if I haven’t received a notice?

Keep watching your mail, and consider contacting us now so we can track your case as this situation develops. If you do receive a notice letter, save it and reach out right away.

What information was exposed at the confirmed Flynn Group entities?

It varies by entity. Some confirmed notices describe only employment data broadly, while others itemize Social Security numbers, medical records, financial account information, and driver’s license numbers. Whether the same categories would apply to a Planet Fitness breach, if confirmed, is not yet known.

Do I have a legal claim?

You may, if your information was involved. Employers are required by law to protect the personal information employees provide to them. If you are a current or former Flynn Group Planet Fitness employee and believe you were affected, contact the Data Breach Attorneys at Emery | Reddy at 916.995.5968 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.

"Very friendly interview and intake process. I was informed thoroughly about the processes in obtaining a lawyer and was given ample time to make a decision on representation. I’m thankful for everyone’s help and looking forward to working with this Firm on my worker’s compensation claim."

- Darren A.

Receive a
FREE Case Review

Call Now