UPBOUND GROUP, INC.

Jul 2026 · Graded Verified · Professional and Business Services · Government record

Incident summary

UPBOUND GROUP, INC.Jul 2026
$13M
Spent responding & recovering
Direct expense
Upbound rated the stolen customer information non-sensitive, right up until it was enough to open roughly $13 million in fraudulent Acima leases and walk the merchandise out the door. The breach turned lease-to-own approval into a front door for anyone holding the right paperwork: identity verification that trusted data the company itself had graded as low value. No group has claimed it and no customer count has surfaced, leaving the theft measured only by the fraud it financed.
Verified: the linked document states this figure.
Professional and Business Services
SEC 8-K, Item 8.01
Initial attack type not disclosed · Impact data theft confirmed + financial theft or fraud
Quantified 9 days after disclosure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
2026-07-31$13MVVerifiedSEC 10-Q ↗

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index