Upbound Group's Data Breach Cost It $13 Million in Fake Lease Agreements
Texas-based consumer finance firm Upbound Group has disclosed that hackers broke into its systems and walked away with enough customer data to run a convincing fraud operation — one that ultimately cost the company around $13 million.
Upbound operates Rent-A-Center, Acima, and Brigit, all focused on lease-to-own and flexible payment products. It's the kind of business where customer data has obvious and immediate practical value to fraudsters.
In an SEC filing, Upbound confirmed that non-sensitive customer information and related documents were taken. Whoever got hold of it apparently wasted no time putting it to use. The company believes the stolen data was used to fabricate fraudulent lease-to-own contracts, with the losses concentrated in its Acima segment during Q2 2026.
Thirteen million dollars. In one quarter. From one segment. That's a reasonably costly breach for data the company itself describes as non-sensitive.
Law enforcement has been notified, and external cybersecurity consultants have been brought in to patch whatever gaps let this happen. The investigation is still running, and Upbound's current position is that the incidents don't meet the threshold for materiality under SEC rules — though $13 million in fraudulent losses suggests the practical impact was very real regardless of the legal definition.
No ransomware group or known threat actor has claimed responsibility, and the company hasn't named any suspects. For now, attribution is an open question.