Upbound Group, Inc.
bd_cda23c6fd7ac708e · schema v1 · pii pii-v1
Full breach record for Upbound Group, Inc. →Upbound Group, Inc. disclosed cybersecurity incidents involving unauthorized access to non-sensitive customer information and documents. The company believes the data was used to facilitate fraudulent lease-to-own agreements, contributing to about $13 million in fraudulent contract losses in its Acima segment in Q2 2026. It implemented enhanced authentication and fraud detection and notified federal law enforcement. The investigation is ongoing; the company deems the incidents immaterial.
J jump to incidentP pin to compareR raw source
Incident timeline — partial
? — ?
Breach window unknown
Jul 22, 2026
Filed
—
No filing yet · watching
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.