Skip to content
Data breachContained

Upbound Group (Acima) data compromise enables $13 million in fraudulent leases

Lease-to-own company Upbound Group disclosed in an SEC filing that customer data obtained in cybersecurity incidents was used to open fraudulent Acima lease agreements, causing about $13 million in losses in the second quarter of 2026.

Victim
Upbound Group, Inc.
Loss
$13.0M

On 21 July 2026, Upbound Group, the Texas-based parent of lease-to-own brands Rent-A-Center, Acima and Brigit, disclosed in a Form 8-K filed with the U.S. Securities and Exchange Commission that cybersecurity incidents had led to roughly $13 million in fraudulent contract losses in its Acima segment during the second quarter of 2026.

According to the filing, certain non-sensitive customer information and other documents were obtained without authorization and then used to facilitate fraudulent lease-to-own agreements. The company said that once it identified the compromise it began mitigation and remediation, including enhanced authentication controls and additional fraud detection and monitoring, and it notified federal law enforcement.

What we know

Upbound said its investigation was ongoing and that, at the time of the filing, it did not consider the incidents material. It did not say how the data was obtained or how many customers were affected. No known cybercrime or extortion group listed the company on a leak site, which suggests a fraud operation focused on monetizing data directly rather than on extortion.

Why it matters

The case is a clear example of a breach with a measurable financial impact even though the stolen data was described as "non-sensitive": combined with weak identity verification in a fast online approval flow, basic customer details were enough to originate leases in other people's names. It shows why fraud losses, not only notification and response costs, belong in the cost of a data compromise for consumer lenders.

Financial impact

Reported costs in USD

Total reported loss
13.0M
USD · $13,000,000
  • Business loss$13.0M

Timeline

  1. Upbound files a Form 8-K disclosing cybersecurity incidents that led to about $13 million in fraudulent contract losses in its Acima segment during Q2 2026.

  2. Media reports note that no known extortion group has claimed the incidents.

Sources

  1. sec.govhttps://www.sec.gov/Archives/edgar/data/0000933036/000119312526310605/upbd-20260721.htm
  2. securityweek.comhttps://www.securityweek.com/upbound-group-says-data-breach-led-to-13-million-in-fraudulent-contract-losses/

Related incidents

Data breachOngoing

Fortune 500 Azure/Entra ID data theft (TheHatman)

A threat actor using the handle TheHatman advertised roughly 3.64 million employee directory records scraped from the Microsoft Azure and Entra ID tenants of multiple Fortune 500 companies, with access reportedly gained through stolen credentials harvested by infostealer malware.

Victim
Multiple Fortune 500 companies (Azure/Entra ID tenants)
Records
3.6M