Upbound Group Data Breach Exposes Customer Information Used for Fraud

Finance data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: July 2026

What Happened in the Upbound Group Data Breach?

Upbound Group, the company behind the Acima Leasing and Rent-A-Center brands, has confirmed that hackers broke into its systems and stole customer information. The company disclosed the incident in a filing with the U.S. Securities and Exchange Commission. As a result, Upbound now says the stolen data was used to commit widespread fraud within its Acima lease-to-own program.

According to the filing, attackers obtained certain customer information and other documents without authorization. The company described the data as non-sensitive, but it was still detailed enough to let criminals impersonate real customers. Because of this, fraudsters were able to open fraudulent lease-to-own agreements through Acima’s system using stolen identities.

Through these fake agreements, the criminals acquired merchandise from retailers that partner with Acima. Acima paid those retailers as it normally would for legitimate leases. However, the fraudsters walked away with the goods and never made a single lease payment, leaving Upbound with the loss.

Upbound says it began investigating as soon as it detected the intrusion. The company brought in outside cybersecurity experts to help determine how the attackers got in and what data they accessed. This investigation is still active, and Upbound has stated it may take further action depending on what investigators find.

Who was affected?

The individuals affected are customers who used or applied for Acima’s lease-to-own services. Because Acima works with numerous third-party retailers and e-commerce sites, the pool of potentially affected people could span a wide customer base across multiple states. Upbound has not publicly disclosed the exact number of customers whose information was compromised.

Since Acima’s lease-to-own model is often used by consumers seeking flexible payment options for everyday goods, the affected population likely includes people across a broad range of income levels and locations. There is currently no confirmation of whether minors were included among those affected. Upbound has also not clarified whether employees, in addition to customers, had information exposed.

What Information Was Potentially Exposed?

Upbound has been relatively limited in detailing exactly what data was taken, describing it broadly as customer information and related documents. Even though the company characterized this information as non-sensitive, it was clearly sufficient for criminals to pose as real customers and open fraudulent accounts. This suggests the stolen data included identifying details tied to real people.

  • Customer names
  • Contact information potentially including addresses or phone numbers
  • Account-related documents used to verify identity for lease agreements
  • Other unspecified customer records held by Acima

Because this data was used to successfully open fraudulent lease-to-own agreements, it likely included enough personal detail to pass identity checks. This is a meaningful concern for affected customers. Even information that a company labels as non-sensitive can still enable identity theft if it includes names, addresses, or account numbers that criminals can combine with other stolen data.

As a result, affected individuals should not assume they are safe simply because Upbound described the exposed data as non-sensitive. Criminals often combine seemingly minor details from multiple sources to build a convincing false identity. This can lead to unauthorized accounts, damaged credit, and long-term recovery headaches for victims who are not even aware their information was misused.

What is the company doing?

Once Upbound detected the unauthorized access, it moved to contain the damage and prevent further fraud. The company implemented enhanced authentication controls to make it harder for criminals to open new accounts using stolen information. In addition, it added new fraud-detection mechanisms and improved monitoring across its systems.

Upbound also notified federal law enforcement authorities about the incident, allowing investigators to pursue the responsible parties. The company says its internal investigation is ongoing and that it will take additional steps based on future findings. Upbound has stated that, so far, the incident does not appear significant enough to affect its overall financial outlook, though the $13 million in fraud losses were disclosed as a direct result of the breach.

What Should Affected Individuals Do?

Monitor Your Credit Reports Closely

Anyone who has used Acima’s lease-to-own services should check their credit reports regularly for signs of unfamiliar activity. This includes unfamiliar accounts, unexpected inquiries, or lease agreements you never signed up for. Catching fraud early can make a major difference in how quickly it gets resolved.

You can request free credit reports from all three major credit bureaus. Reviewing these reports every few months, rather than just once, helps you spot new fraudulent activity as soon as it appears. If you notice anything suspicious, dispute it immediately with the bureau and the creditor involved.

Consider a Fraud Alert or Credit Freeze

Because this breach directly led to fraudulent lease accounts being opened in victims’ names, placing a fraud alert or credit freeze is a smart precaution. A fraud alert requires lenders to verify your identity before extending credit. A credit freeze goes further by blocking new accounts from being opened altogether.

Setting up either protection is free and can typically be done online or by phone with each credit bureau. While a freeze offers stronger protection, it does require you to lift it temporarily whenever you apply for new credit yourself. Given that fraudsters already used stolen data to open fake leases here, this extra step is worth the minor inconvenience.

Watch for Phishing Attempts

After a breach like this, criminals often follow up with phishing emails or text messages designed to look like they come from Acima, Upbound, or a related retailer. These messages may ask you to confirm account details or click a suspicious link. Always verify the sender before responding to any unexpected message.

If you receive a message claiming to be from Acima or Upbound, contact the company directly using its official website or customer service number rather than replying. This ensures you are not handing over additional information to the same criminals responsible for the original breach. Never provide sensitive details in response to an unsolicited message.

Review Any Existing Lease-to-Own Agreements

If you have an active or past Acima lease, take time to review your account statements carefully. Look for payments, items, or agreements you do not recognize. Because the fraud in this case involved fake leases being opened, your genuine account history is the clearest place to spot irregularities.

Should you find anything unusual, report it to Acima’s customer service and request a written explanation. Keep copies of all correspondence in case you need to dispute charges or provide documentation later. This paper trail can also be useful if you decide to consult a data breach attorney about your options.

Know Your Legal Options

If your information was compromised and misused as a result of this breach, you may have legal options worth exploring. Consulting with a data breach attorney can help you understand whether you qualify for compensation. Many attorneys offer free case evaluations, so there is little downside to asking.

Because this breach directly resulted in documented financial fraud, affected consumers may have a stronger basis for pursuing claims than in cases involving exposure alone. An attorney can review your specific situation and explain what evidence you would need. This is especially useful if you discover unauthorized leases or accounts tied to your name.



Related Data Breaches