CSIDB logo
Incident

Upbound Group

Incident posture

Attack window
Q2 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-01 11:14

Linked entities

Victim
Upbound Group
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Q2 2026
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Upbound Group reported that hackers accessed non-sensitive customer data and documents, which were used to create fraudulent lease-to-own agreements, leading to $13 million in losses in its Acima segment during Q2 2026. No ransomware group claimed the breach.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Upbound Group, Inc., a Texas-based consumer finance company that operates lease-to-own and flexible payment brands such as Rent-A-Center, Acima, and Brigit, disclosed in a filing with the U.S. Securities and Exchange Commission that it had fallen victim to a cybersecurity incident resulting in the theft of non-sensitive customer information and other corporate documents. According to the filing, the stolen information was subsequently used by threat actors to facilitate fraudulent lease-to-own agreements, which contributed to elevated fraudulent contract losses of approximately $13 million within the company's Acima segment during the second quarter of 2026. At the time of disclosure, Upbound stated its investigation was ongoing and that the incidents were not believed to be material, while the specific technical vector used by the attackers to obtain access to the data was not publicly identified.

The stolen data was described in the SEC filing as "non-sensitive customer information and other documents," though the exact categories of information compromised were not enumerated in public reporting. Following the discovery of the breach, Upbound Group notified law enforcement authorities and engaged external cybersecurity experts to assist with bolstering the security of its systems and to investigate the scope and origin of the intrusion. The company did not disclose whether any ransomware component, encryption event, or operational disruption accompanied the data theft, and the timeline of the original intrusion was not made public. No publicly known cybercrime group claimed responsibility for the incident at the time of reporting, and Upbound Group was not listed on any known dark web leak site associated with major ransomware or extortion operations.

The financial impact of the breach was concentrated in the company's Acima segment, where fraudulent lease-to-own agreements were originated using the stolen customer and document data, resulting in the $13 million loss figure cited in the SEC filing. The distinction between the Acima segment and the broader Rent-A-Center and Brigit operations suggests the fraudulent activity was tied specifically to the lease-to-own products underwritten through Acima's business processes. Upbound's characterization of the stolen data as "non-sensitive" appears in tension with the demonstrated ability of the threat actors to use that information to successfully originate fraudulent contracts, indicating that even data classified as non-sensitive can enable significant downstream financial fraud when paired with internal documentation obtained during the intrusion. The company filed its disclosure with the SEC in accordance with regulatory obligations governing publicly traded companies, signaling that the incident had reached a threshold of financial or operational significance requiring public reporting despite the company's assessment that the incidents themselves were not material.

Upbound's response combined internal investigation with external remediation support, including coordination with law enforcement and third-party cybersecurity specialists tasked with hardening system defenses and identifying the full scope of unauthorized access. The company stated that the security of its systems was being enhanced as part of the post-incident response, though specific technical controls, system changes, or identity and access management adjustments implemented after the breach were not detailed in public reporting. The absence of any claimed attribution, any identified initial access vector, and any confirmed timeline left several aspects of the incident unresolved in the public record. At the time of the filings and contemporaneous reporting in late July 2026, the investigation remained open, and the full extent of the data exposure and the identity of the threat actors had not been publicly confirmed.

Sources

Sources available to members: 2 sources.

CSIDB