Upbound Group Says Data Breach Led to $13 Million in Fraudulent Contract Losses
Texas-based consumer finance company Upbound Group, Inc. says recent cybersecurity incidents led to a data breach that resulted in millions of dollars in fraudulent contract losses.
Upbound offers lease-to-own and flexible payment solutions through brands like Rent-A-Center, Acima, and Brigit.
In a filing with the SEC, the company said non-sensitive customer information and other documents were recently obtained by hackers.
Upbound believes “the information was subsequently used to facilitate fraudulent lease-to-own agreements, contributing to elevated fraudulent contract losses of approximately $13 million in the Company’s Acima segment during the second quarter of 2026.”
The company has notified law enforcement and hired external cybersecurity experts to help boost the security of its systems.
Upbound’s investigation is ongoing, but at the time of the SEC disclosure it believes the incidents are not material.
It’s unclear who is behind the attacks on Upbound. No known cybercrime group appears to have listed the company on its leak website.
A longtime cybersecurity executive recently launched The Hacker in a Hoodie (HIH) Index, a tracker for material breaches that can be useful to cybersecurity professionals, journalists, policymakers, and others.
Related: Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
Related: Ransomware Group Threatening to Leak Data Stolen From Coca-Cola’s Fairlife
Related: Estée Lauder Discloses Impact From Oracle EBS Zero-Day Hack