Skip to content
Upbound Group Faces $13 Million Loss from Data Breach and Fraudulent Leases

Upbound Group Faces $13 Million Loss from Data Breach and Fraudulent Leases

First seen 23 Jul 2026, 18:34 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster July 24, 2026 at 16:20 UTC
  • Upbound Group reported $13 million in losses due to a data breach and subsequent fraud.
  • Threat actors exploited stolen customer data to create fraudulent lease agreements.
  • The company is enhancing security measures and has notified federal law enforcement.

Upbound Group reported a data breach that allowed threat actors to steal non-sensitive customer information, leading to $13 million in fraudulent lease agreements through its Acima segment. The attackers exploited the stolen data to obtain goods via Acima's lease-to-own system, which were then not paid for. The incident was disclosed in an SEC filing, and the company has begun implementing enhanced security measures with external cybersecurity experts. Federal law enforcement has been notified, and the investigation is ongoing. No ransomware groups have claimed responsibility for the attack. Upbound Group, previously known as Rent-A-Center, is focused on mitigating the impact of this breach and preventing future incidents.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 60d ago How this analysis works

Timeline

2026-07-22
Upbound Group discloses data breach
The company reported a breach that allowed unauthorized access to non-sensitive customer information, leading to significant financial losses.
Bleepingcomputer
2026-07-22
Fraudulent leases generated
Threat actors used stolen data to fraudulently obtain goods through Acima's system, resulting in $13 million in losses.
Bleepingcomputer
2026-07-22
Mitigation measures initiated
Upbound began implementing enhanced authentication and fraud detection measures with the help of cybersecurity experts.
Bleepingcomputer
2026-07-22
Federal law enforcement notified
Upbound Group reported the incident to federal authorities as part of their response to the breach.
Bleepingcomputer

More articles in this cluster (5)

Following this threat?

Track Acima in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed