RB American Group Data Breach Exposes SSNs and Protected Health Information

Published
September 10, 2026
Updated
September 10, 2026
RB American Group Data Breach Exposes SSNs and Protected Health Information
Reckitt Benckiser
Affected by the data breach? You may be entitled to compensation. Submit a claim today.

RB American Group LLC, a major Arby's franchise operator, disclosed a data breach that exposed sensitive employee information after an unauthorized actor accessed its network in April 2026. The company is a wholly owned subsidiary of Flynn Restaurant Group LP.

Notably, the Apple American Group, the Bell American Group, the Hut American Group and the Pan American Group reported data breaches, although it remains unclear if the incidents are connected.

The company began notifying affected individuals on Aug. 28, 2026. So far, 974 Washington residents and four Massachusetts residents were impacted.

On April 9, 2026, RB American Group became aware of suspicious activity on its network and took steps to secure its systems. The company then launched a comprehensive investigation to determine the full nature and scope of the activity.

The investigation found that an unknown actor accessed certain servers between April 8, 2026, and April 9, 2026, and accessed or acquired certain files during that time. With the assistance of third-party specialists, the company reviewed the affected files to identify the types of sensitive information they contained and the individuals whose data was involved.

The types of personally identifiable information exposed included names, Social Security numbers, financial information such as banking details and credit or debit card numbers, driver's license or state ID card numbers, full dates of birth, passport numbers, military ID numbers, student ID numbers, taxpayer ID numbers, digital credentials, such as usernames with passwords, email addresses with passwords, security question answers and unique private keys used for electronic authentication.

Protected health information was involved as well, including health insurance policy or ID numbers, medical information and biometric data.

RB American Group's response to the breach

RB American Group is offering affected individuals 24 months of free credit monitoring and identity theft protection services through TransUnion. To enroll, individuals can visit the Cyberscout enrollment page and enter the unique code included in their notification letter. Enrollment must be completed within 90 days of the letter's date.

For additional questions, affected individuals can contact the company's dedicated assistance line Monday through Friday between 8 a.m. and 8 p.m. EST, excluding U.S. holidays. Individuals may also write to RB American Group LLC at Attn: Legal Department, 6200 Oak Tree Blvd., Suite 250, Independence, OH 44131, or call 216-525-2775.

SUBMIT YOUR CLAIM TO THE LAW FIRM HANDLING THIS INVESTIGATION

Types of INFORMATION affected
  • Names
    Names
  • Social security numbers
    Social Security Numbers
  • Dates of birth
    Dates of Birth
  • Addresses
    Addresses
  • Government IDs
    Government IDs
  • Medical Information
    Medical Info
  • Financial Info
    Financial Info
  • Affected information types not yet disclosed

Notice Letter

This browser does not support inline PDFs. Please download the PDF to view it: Download PDF

Affected Entity
Reckitt Benckiser
Consumers Notification date
Date of Breach
April 8, 2026
Breach Discovered Date
Total People Affected
Information Types Exposed
  • Name
  • Social Security Number
  • Driver's License or Washington ID Card Number
  • Financial & Banking Information
  • Credit/Debit Numbers
  • Full Date of Birth
  • Unique Private Key (e.g. used to authenticate or sign
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image
CTA Image