Upbound: Data breach led to $13M fraud in Acima segment
Upbound Group says a recent data breach caused about $13 million in fraudulent lease-to-own contract losses in its Acima segment in Q2 2026.
Upbound Group Inc., a Texas-based consumer finance company, reported a cybersecurity incident that led to roughly $13 million in fraudulent lease-to-own contract losses in its Acima segment during the second quarter of 2026, according to an SEC filing.
The filing states attackers obtained non-sensitive customer information and other documents that were subsequently used to open fraudulent lease-to-own agreements, contributing to the losses in the Acima business.
Upbound notified law enforcement and retained external cybersecurity experts to strengthen its systems. The company says its investigation is ongoing and that, at the time of the SEC disclosure, it did not view the incidents as material to the business overall.
The filing did not name any perpetrators and noted there were no public claims on known cybercrime leak sites when the disclosure was made.
Upbound did not detail whether it has made remedial payments to affected customers, whether customers will receive direct notifications beyond the SEC filing, whether ransom demands were involved, or whether all compromised access points have been fully secured.
A newly launched tracker, the Hacker in a Hoodie (HIH) Index, aims to catalog material data breaches to help security teams and policymakers monitor incidents. Forensic work will be required to determine precisely how the fraud was carried out and whether additional customer protections or system changes are needed.
Upbound operates lease-to-own and flexible payment services under brands including Rent-A-Center, Acima and Brigit.








