Upbound Group disclosed that attackers gained unauthorized access to certain non-sensitive customer information and other documents, and the stolen data was later used to create fraudulent lease-to-own agreements through its Acima segment. The company said the abuse of that information contributed to roughly $13 million in elevated fraudulent contract losses in the second quarter, as fraudsters allegedly obtained goods through Acima while participating retailers were paid and the leases went unpaid.
Upbound said it launched mitigation and remediation efforts after detecting the incidents, including stronger authentication controls, added fraud detection and monitoring, and other security improvements with support from external cybersecurity experts. The company notified federal law enforcement and said its investigation remains ongoing; it has not identified the attackers publicly, no ransomware or extortion group had claimed responsibility, and the company said that based on its current understanding it does not believe the incidents are material, though that assessment could change.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
In a Form 8-K dated July 21, 2026, Upbound Group disclosed the cybersecurity incidents, the related fraudulent Acima lease activity, and its response measures. The company said that based on its current understanding, it did not believe the incidents were material, though that assessment could change.
The company said it notified federal law enforcement after the incidents came to light. Upbound also stated that its investigation remains ongoing.
Upbound said information taken in the incidents was later used to facilitate fraudulent lease-to-own agreements through its Acima segment. The company attributed approximately $13 million in elevated fraudulent contract losses during the second quarter of 2026 to this activity.
Upbound Group said it recently identified cybersecurity incidents involving unauthorized access to certain non-sensitive customer information and other documents. After identifying the compromise, it began mitigation and remediation efforts including enhanced authentication, additional fraud detection and monitoring, and other security improvements with help from external cybersecurity experts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcescworld.com
Open sourcesecurityweek.com
Open sourcecyberveille.ch
Open sourcecyberveille.ch
Open sourcebleepingcomputer.com
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.