Find notable cyber news and cases, enriched with sources, timelines, and signals.

Upbound Group hit by ransomware attack

Incident
First reported
Last updated
Happening score
H score 45
1 unique sources, 1 articles

Summary

Hide ▲

Upbound Group disclosed a cybersecurity incident in which attackers obtained customer information without authorization and used it to drive fraudulent Acima lease-to-own agreements, causing about $13 million in losses. The company said it responded with external cybersecurity experts, new fraud controls, and improved monitoring, and it notified federal law enforcement. No public ransomware or extortion claim had been made at disclosure time.

Related Happenings

Upbound Group customer data obtained without authorization

Data Leak
H score44 First: 23.07.2026 00:43 Last: 23.07.2026 00:43 Sources 1

How related: experienced cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization.

About this happening: Upbound Group's customer information and documents were obtained without authorization, confirming a data-leak event that enabled downstream fraud in Acima. The expose...

Timeline

  1. 23.07.2026 00:43 2 articles · 1h ago

    Upbound Group discloses fraudulent Acima lease losses after customer data theft

    Initial Disclosure

    Upbound Group disclosed in an SEC filing that attackers obtained non-sensitive customer information and other documents without authorization and used them to create fraudulent Acima lease-to-own agreements, causing about $13 million in losses in the Acima segment in the second quarter of 2026. Upbound said it began mitigation and remediation with external cybersecurity experts, added enhanced authentication controls, additional fraud-detection mechanisms, and improved monitoring, and notified federal law enforcement.

    Show sources