← BACK TO FEED
data breachfraudUpbound GroupSEC disclosureconsumer finance

Upbound Group's Data Breach Cost It $13 Million in Fake Lease Agreements

Texas-based consumer finance company Upbound Group disclosed in an SEC filing that a recent data breach, in which hackers obtained non-sensitive customer information, was used to facilitate fraudulent lease-to-own agreements. The incident resulted in approximately $13 million in fraudulent contract losses within its Acima segment during the second quarter of 2026. The company has notified law enforcement, engaged external cybersecurity experts, and considers the breach non-material, though its investigation remains ongoing.

Texas-based consumer finance firm Upbound Group has disclosed that hackers broke into its systems and walked away with enough customer data to run a convincing fraud operation — one that ultimately cost the company around $13 million.

Upbound operates Rent-A-Center, Acima, and Brigit, all focused on lease-to-own and flexible payment products. It's the kind of business where customer data has obvious and immediate practical value to fraudsters.

In an SEC filing, Upbound confirmed that non-sensitive customer information and related documents were taken. Whoever got hold of it apparently wasted no time putting it to use. The company believes the stolen data was used to fabricate fraudulent lease-to-own contracts, with the losses concentrated in its Acima segment during Q2 2026.

Thirteen million dollars. In one quarter. From one segment. That's a reasonably costly breach for data the company itself describes as non-sensitive.

Law enforcement has been notified, and external cybersecurity consultants have been brought in to patch whatever gaps let this happen. The investigation is still running, and Upbound's current position is that the incidents don't meet the threshold for materiality under SEC rules — though $13 million in fraudulent losses suggests the practical impact was very real regardless of the legal definition.

No ransomware group or known threat actor has claimed responsibility, and the company hasn't named any suspects. For now, attribution is an open question.

READ NEXT
Clover Health Investments Hit by Social Engineering Attack, Patient Data ExposedAnubis Ransomware Gang Claims Fairlife Hit, Gives Coca-Cola One Week to PayEstée Lauder Confirms Employee Data Stolen in Oracle EBS Zero-Day Attack