Upbound Group, Inc., a financial services company that operates the lease-to-own brands Rent-A-Center and Acima Leasing, has disclosed a cybersecurity incident in which unauthorized actors gained access to customer information. The company reported that stolen data was then used to fraudulently create lease-to-own agreements through its Acima Leasing platform.
Companies that hold customer account records and personal information have a responsibility to protect that data from unauthorized access. When a breach like this one leads to real financial harm, such as fraudulent accounts opened in a customer’s name, the impact on affected individuals goes well beyond a simple data exposure.
Upbound Group’s Data Breach Investigation
Upbound Group disclosed the cybersecurity incident to the U.S. Securities and Exchange Commission on July 21, 2026. According to the company’s disclosure, unauthorized actors gained access to certain customer information and related documents, and the stolen data was allegedly used to fraudulently create lease-to-own agreements through the company’s Acima Leasing platform. Details about the breach were also posted publicly on an open web network on July 23, 2026, corroborating that customer data had been compromised.
The company has described the compromised information only in general terms as customer information and related documents, and has not published a specific, itemized list of the data types involved or the total number of individuals affected in the United States. Upbound Group stated it has implemented additional security controls and strengthened its fraud detection and monitoring capabilities in response to the incident, and that its investigation remains ongoing.
Breaches that result in fraudulently created financial accounts or lease agreements, as reportedly occurred here, represent one of the more serious forms of harm a data breach can cause, distinct from a breach where data is merely exposed but not yet actively misused. When stolen account information is used to open new lines of credit or leases in a victim’s name, the resulting damage to that person’s credit history and finances can take months or years to fully unwind, even after the fraudulent accounts are identified and closed.
Companies in the lease-to-own and consumer finance space are attractive targets for cybercriminals because they routinely collect the type of identifying and financial information, names, addresses, payment history, and account credentials, that can be repurposed to open new fraudulent accounts elsewhere. The public posting of breach details on an open web network, as reportedly happened in this incident, is also a common pattern that increases the risk of the stolen data being bought, sold, or used by multiple bad actors rather than a single one.
Individuals who do business with Rent-A-Center, Acima Leasing, or another Upbound Group brand should treat any unexpected account activity, unfamiliar lease agreements, or unusual credit inquiries as a potential red flag connected to this incident, even before receiving a formal notification letter.
When Did This Breach Occur?
Upbound Group disclosed the cybersecurity incident to the SEC on July 21, 2026. Details about the breach were also posted publicly on an open web network on July 23, 2026. The company has not published a specific date on which the underlying unauthorized access first occurred.
What Information Was Breached?
Upbound Group has described the compromised information only as customer information and related documents used on its Acima Leasing platform. The company has not published an itemized list of the specific data elements involved, such as names, Social Security numbers, or account numbers. Individuals who receive a direct notification letter from Upbound Group should review it carefully, as it will specify exactly what information of theirs was affected.
What You Can Do
If you have an account with Rent-A-Center, Acima Leasing, or another Upbound Group brand, consider taking the following steps:
- Review your Rent-A-Center or Acima account statements for any lease agreements or charges you do not recognize
- Enroll in any free credit monitoring or identity protection services offered
- Place a fraud alert or credit freeze with the three major credit bureaus
- Regularly check your credit report for unfamiliar accounts or hard inquiries
- Change your account password and enable additional security features if available
- Keep any data breach notification letter you receive for your records
File a Data Breach Lawsuit Against Upbound Group
If your information was involved in the Upbound Group data breach, especially if fraudulent accounts or leases were opened in your name, you may have legal options. Companies that store customer account information are expected to implement reasonable safeguards to prevent this kind of unauthorized access and misuse.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.