← Upbound Group

2026 Upbound Group — cyber incidents; stolen customer data used for ~$13M fraudulent Acima leases

2026 Unknown records affected Share on X

Data compromised

Per SEC Form 8-K: certain non-sensitive customer information and other documents obtained without authorization; used to obtain goods via fraudulent Acima leases causing ~$13M Q2 losses. Customer headcount not disclosed.

Technical writeup

Verified SEC disclosure — July 21–22, 2026. Upbound Group, Inc. (formerly Rent-A-Center) reported cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization. Attackers used the stolen information to create fraudulent Acima lease-to-own agreements; Acima paid retailers for merchandise that fraudsters took without making lease payments, producing about $13 million in Acima-segment losses in Q2 2026. Upbound said it enhanced authentication and fraud detection, notified federal law enforcement, and continues investigating; it characterized the incident as not material to investment decisions in the filing’s framing. No ransomware group publicly claimed the attack at BleepingComputer’s reporting. BreachHistory retains recordsAffected 0 pending an attested customer count.

Root cause

Unauthorized acquisition of certain non-sensitive customer information and other documents; attackers used stolen data to create fraudulent Acima lease-to-own agreements (SEC disclosure)

References