
Upbound Group Inc., a financial services company that operates lease-to-own brands including Rent-A-Center and Acima Leasing, disclosed a cybersecurity incident in which unauthorized actors accessed customer information.
The breach was disclosed to the U.S. Securities and Exchange Commission on July 21, 2026. The total number of individuals affected in the United States has not been publicly reported.
Unauthorized actors gained access to certain non-sensitive customer information and related documents belonging to Upbound Group. The stolen data was then allegedly used to fraudulently create lease-to-own agreements through the company's Acima Leasing platform.
Details about the breach were also posted publicly on an open web network on July 23, 2026. The posting confirmed the incident as a data breach involving unauthorized access to customer data. No specific threat actor has been named in connection with the incident.
The company described the compromised information as non-sensitive customer information and related documents. A detailed list of the specific types of personal data involved has not been made publicly available.
Upbound Group implemented additional security controls across its systems. The company strengthened its fraud detection and monitoring capabilities in an effort to identify and prevent further misuse of the accessed information, according to available disclosures.
The investigation into the breach remains ongoing, and additional findings may be disclosed as the inquiry progresses.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)