[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fTN5ZojbRNKvR_BHsYAgfE2Y5Kvd23-fOiXU9-9gsYf4":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":21,"source":22,"isVerified":4,"isSpamList":23,"isSensitive":4,"severity":24,"processingStatus":25,"logoUrl":26,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66950fc779fb66f04722cb","UpboundGroup2026","Upbound Group 2026 Data Breach","upbound-group-2026","upbound.com",{"name":12,"sector":13,"country":14,"website":10},"Upbound Group","Financial Services","United States","2026-07-21T00:00:00.000Z","2026-07-26T23:15:27.875Z",0,[19,20],"Non-sensitive customer information","Other documents","\u003Cp>\u003Cstrong>The Upbound Group 2026 data breach\u003C\u002Fstrong> consists of cybersecurity incidents in which the financial-technology and lease-to-own company confirmed in an SEC filing that certain non-sensitive customer information and other documents were obtained without authorization. Upbound believes information from certain incidents was later used to facilitate fraudulent lease-to-own agreements, contributing to approximately $13 million in elevated fraudulent contract losses in its Acima segment during the second quarter of 2026.\u003C\u002Fp>\n\u003Cp>The primary source is Upbound Group's Form 8-K dated July 21, 2026. BleepingComputer independently reviewed the filing and reported the data compromise, its fraud impact on Acima, and the company's response. The SEC disclosure does not provide exact access dates, an affected-person count, or individual customer-data fields. LeakData therefore uses the disclosure date as a time reference and keeps the affected-person total unknown.\u003C\u002Fp>\n\u003Ch2>Confirmed Data Scope\u003C\u002Fh2>\n\u003Cp>Upbound's confirmed data classes are “certain non-sensitive customer information” and “other documents.” The company did not break those descriptions into more detailed fields. Names, addresses, phone numbers, email addresses, Social Security numbers, payment data, identity documents, credit information, and passwords are not individually listed in the public filing. LeakData therefore displays only the broad categories used by the company.\u003C\u002Fp>\n\u003Cp>The filing uses the plural phrase “cybersecurity incidents,” and it does not say whether they shared one access path, actor, or system. The contents and number of documents, data volume, and number of customers represented are also unknown. Upbound's overall customer scale and Acima's lease volume are not breach counts; the pwnCount is zero because no verified affected-person total has been published.\u003C\u002Fp>\n\u003Ch2>Acima Fraud and the $13 Million Loss\u003C\u002Fh2>\n\u003Cp>Upbound believes information obtained without authorization was subsequently used in connection with certain incidents to facilitate fraudulent lease-to-own agreements. BleepingComputer's account of the SEC filing explains that stolen customer data and documents were used to obtain goods through Acima; Acima paid participating retailers, while the fraudulent agreements did not produce the required lease payments. This link shows a confirmed business impact rather than merely a theoretical data risk.\u003C\u002Fp>\n\u003Cp>The approximately $13 million figure describes elevated fraudulent contract losses in Upbound's Acima segment during the second quarter of 2026. It is not the market value of stolen data, a ransom payment, the number of affected customers, or necessarily the exact proceeds of one actor. Because the company says the incidents “contributed” to the losses, it would also be inaccurate to attribute every dollar exclusively to one cyber event.\u003C\u002Fp>\n\u003Ch2>Timing and Investigative Limits\u003C\u002Fh2>\n\u003Cp>The Form 8-K gives July 21, 2026 as its report date and date of the earliest event reported, but its narrative says only that Upbound “recently experienced” the cybersecurity incidents. The start and end of unauthorized access and the date on which the company first detected the compromise are not public. July 21 is therefore a verified disclosure reference in this record, not a claim that the attacker first entered a system that day.\u003C\u002Fp>\n\u003Cp>The investigation remained ongoing when the filing was published. Upbound said it would make legal or regulatory notifications as appropriate based on the findings. On the quantitative and qualitative facts then known, the company considered the incidents not material to investor decisions and said it would reassess if circumstances changed substantially. A securities-law materiality conclusion does not mean that the confirmed data compromise did not occur.\u003C\u002Fp>\n\u003Ch2>Upbound's Response\u003C\u002Fh2>\n\u003Cp>After identifying the data compromise, Upbound said it promptly began mitigation and remediation in coordination with external cybersecurity experts. The disclosed measures include enhanced authentication controls, added fraud-detection and monitoring capabilities, and other security improvements. The company also notified federal law enforcement and said it would take further action as warranted by the continuing investigation.\u003C\u002Fp>\n\u003Cp>Upbound did not disclose the actor, exploited weakness, compromised account or session, exfiltration method, or date on which the environment was fully secured. No ransomware or data-extortion group had publicly claimed the incident by the news report. Those gaps mean that phishing, credential theft, a vendor compromise, or a ransom payment should not be recorded as established fact without additional evidence.\u003C\u002Fp>\n\u003Ch2>Risk for Customers and Retailers\u003C\u002Fh2>\n\u003Cp>Because the information was confirmed to have facilitated fraudulent lease-to-own activity, relevant customers can look for unfamiliar Acima agreements, retailer communications, or unexpected credit-report entries opened in their name. A suspicious agreement or collection message should be checked through a known official Acima or Upbound channel rather than a link in the message. The company had not detailed individual notification at disclosure, so not every customer should assume involvement.\u003C\u002Fp>\n\u003Cp>Retailers participating in Acima can strengthen identity and transaction checks for new lease requests, review unusual device or delivery patterns, and ensure staff understand updated verification procedures. Customers can use unique passwords and multi-factor authentication as general protection, but password theft was not confirmed in this incident. Until specific fields are disclosed, defensive guidance should remain tied to the verified form of lease fraud.\u003C\u002Fp>\n\u003Ch2>How to Interpret This LeakData Record\u003C\u002Fh2>\n\u003Cp>This record documents a data compromise that Upbound Group formally confirmed and connected to actual financial fraud in certain incidents. A zero-person value does not make the event insignificant or fabricated; it records the absence of a public person count. The approximately $13 million figure is not converted into pwnCount because it is a second-quarter fraud-loss amount for the Acima segment, not a record total.\u003C\u002Fp>\n\u003Cp>The verified conclusion is that certain non-sensitive customer information and other documents were obtained without authorization, the information helped facilitate some fraudulent lease-to-own agreements, the activity contributed to approximately $13 million in elevated Acima losses, and Upbound strengthened security and fraud controls. Exact timing, affected-person count, individual fields, and access method remain undisclosed. LeakData presents the event within those limits.\u003C\u002Fp>","Customer information and documents obtained without authorization",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fupbound_com.png"]