2026 Upbound Group — cyber incidents; stolen customer data used for ~$13M fraudulent Acima leases
Data compromised
Per SEC Form 8-K: certain non-sensitive customer information and other documents obtained without authorization; used to obtain goods via fraudulent Acima leases causing ~$13M Q2 losses. Customer headcount not disclosed.
Technical writeup
Verified SEC disclosure — July 21–22, 2026. Upbound Group, Inc. (formerly Rent-A-Center) reported cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization. Attackers used the stolen information to create fraudulent Acima lease-to-own agreements; Acima paid retailers for merchandise that fraudsters took without making lease payments, producing about $13 million in Acima-segment losses in Q2 2026. Upbound said it enhanced authentication and fraud detection, notified federal law enforcement, and continues investigating; it characterized the incident as not material to investment decisions in the filing’s framing. No ransomware group publicly claimed the attack at BleepingComputer’s reporting. BreachHistory retains recordsAffected 0 pending an attested customer count.
Root cause
Unauthorized acquisition of certain non-sensitive customer information and other documents; attackers used stolen data to create fraudulent Acima lease-to-own agreements (SEC disclosure)
References
- https://www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/
- https://www.sec.gov/Archives/edgar/data/933036/000119312526310605/upbd-20260721.htm
- https://www.securityweek.com/upbound-group-says-data-breach-led-to-13-million-in-fraudulent-contract-losses/