Upbound Group Reveals $13M in Fraudulent Contract Losses Due to Data Breach
Texas-based consumer finance company Upbound Group, Inc. disclosed cybersecurity incidents that resulted in a data breach impacting its operations.
The breach led to the unauthorized acquisition of non-sensitive customer data and documents, which were subsequently used to create fraudulent lease-to-own agreements. This activity contributed to approximately $13 million in fraudulent contract losses within the Acima segment during the second quarter of 2026. The company reported the incident to law enforcement and engaged external cybersecurity specialists to enhance its system defenses. Upbound’s ongoing investigation has not yet determined the severity of the breaches, with the company stating the incidents are not material at this time. The identity of the attackers remains unknown, and no cybercrime group has publicly claimed responsibility or listed the organization on its leak platforms. A newly launched tracking tool, the Hacker in a Hoodie (HIH) Index, aims to monitor material breaches for cybersecurity professionals and related stakeholders. The breach highlights vulnerabilities in financial service providers’ data protection measures, underscoring the risks associated with unauthorized access to customer information. The company’s disclosure aligns with regulatory requirements, emphasizing the need for transparency in cybersecurity incidents. No further details about the breach’s technical mechanisms or specific indicators of compromise were provided in the report. The situation underscores the evolving threat landscape for organizations handling sensitive financial data, particularly those operating in the lease-to-own and payment solutions sectors.
