Were you recently affected by a data breach?

RB American Group Data Breach

RB American Group notified individuals on August 28, 2026 of a hacking and IT incident that may have exposed names, Social Security numbers, driver’s license numbers, financial account numbers, and medical records.

RB American Group
Date of Breach: Notice issued August 28, 2026
CAU logo

Who was affected:

Clients of RB American Group

Impacted Data:

Names, Social Security numbers, driver’s license numbers, financial account numbers, and medical records

RB American Group, a multi-brand restaurant franchisee operator, has notified individuals of a hacking and IT incident involving its network. Companies that store employee and customer data, including sensitive financial and medical information, have a responsibility to secure it, and when that security fails, the people affected deserve clear answers about what happened and what is being done about it.

RB American Group’s Data Breach Investigation

RB American Group LLC, a franchise operator affiliated with several national restaurant brands, reported a hacking and IT incident to the Massachusetts Attorney General’s office, with a notice dated August 28, 2026. According to the filing, an unauthorized party accessed the company’s network, though the specific method of intrusion, whether it involved ransomware, phishing, or another technique, has not been publicly disclosed. The filing also does not state a discovery date or the date the incident itself occurred, and it does not disclose how many individuals were affected.

The notification letter sent to affected individuals states that the company found no indication of identity theft or fraud resulting from the incident at the time notice was sent, and that RB American Group has reviewed its existing security policies and implemented additional cybersecurity measures since discovering the event. The company is offering twenty-four months of complimentary credit monitoring and identity theft protection services through TransUnion to individuals who received notice.

Restaurant and franchise operators like RB American Group manage large volumes of both employee data (payroll records, Social Security numbers, banking details for direct deposit) and, depending on the brand and location, customer payment information. This dual exposure makes the franchise and hospitality sector a persistent target for cybercriminals, since a single network intrusion can potentially reach both workforce records and consumer-facing systems depending on how the company’s IT infrastructure is segmented.

The combination of data reportedly involved in this incident, Social Security numbers, driver’s license numbers, financial account numbers, and medical records, is particularly concerning because it spans multiple categories of sensitive information that are each independently valuable to identity thieves. Financial account numbers can enable direct account takeover or fraudulent transfers, while Social Security and driver’s license numbers can be used to open new credit lines or file fraudulent tax returns. Medical records add the additional risk of medical identity theft, where a criminal uses a victim’s identity to obtain medical services or submit fraudulent insurance claims.

Because notification letters for large organizations with many employee and customer records often go out in waves as forensic review continues, individuals connected to RB American Group’s restaurant locations, whether as current or former employees, contractors, or customers, should not assume they were unaffected simply because they have not yet received a letter.

Hacking and unauthorized network access incidents at companies with a large, distributed workforce are especially difficult to fully scope in the days immediately following discovery. A franchise operator managing dozens or hundreds of individual restaurant locations often runs a mix of centralized systems (payroll, human resources, corporate IT) and location-specific systems (point-of-sale terminals, local scheduling software), and an intrusion into one part of that network does not always make clear right away how far the access may have spread. This is one reason notification letters in cases like this one frequently state that a specific discovery date or precise scope has not yet been finalized even after a notice has already been sent.

The offer of complimentary credit monitoring and identity theft protection services is a standard response in incidents involving Social Security numbers and financial account information, since these categories of data are the ones most directly tied to new-account fraud. However, credit monitoring alone does not address the medical identity theft risk that can come from exposed medical records, since fraudulent medical claims and insurance misuse are typically caught through a person’s own insurer or healthcare provider rather than a credit bureau. Affected individuals should treat these as two separate categories of risk requiring two separate kinds of vigilance.

Franchise businesses have increasingly become attractive targets for cybercriminals precisely because a single successful intrusion into a corporate network can potentially expose data connected to many separate restaurant locations and their respective employees at once, rather than requiring an attacker to compromise each location individually.

When Did This Breach Occur?

RB American Group’s notice to affected individuals is dated August 28, 2026. The company has not publicly disclosed the specific dates the underlying hacking and IT incident occurred or when it was discovered.

What Information Was Breached?

According to the regulatory filing, the information that may have been involved includes names, Social Security numbers, driver’s license numbers, financial account numbers, and medical records. The filing does not state that every affected individual had all of these data elements exposed.

What You Can Do

If you received a breach notification letter from RB American Group, consider the following steps:

  • Enroll in the complimentary TransUnion credit monitoring and identity theft protection services offered in the notice within the stated deadline.
  • Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion.
  • Review your bank and financial account statements for unauthorized activity.
  • Check insurance explanation-of-benefits statements for unfamiliar medical claims.
  • Report any suspected identity theft to law enforcement, the Massachusetts Attorney General, and the FTC at IdentityTheft.gov.

File a Data Breach Lawsuit Against RB American Group

If you were notified that your information was involved in the RB American Group data breach, you may have legal options available to you. An attorney experienced in data breach litigation can help you understand your rights and pursue compensation for any harm caused by the exposure of your personal information.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Cybersecurity incident first disclosed September 1, 2026
Date of Breach: Notice issued August 28, 2026
Date of Breach: Incident period reported as November 13-18, 2025; discovered July 27, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.