Breach taxonomy
Summary
Upbound Group disclosed cybersecurity incidents in which non-sensitive customer information and other documents were obtained without authorization and subsequently used to facilitate fraudulent lease-to-own agreements, contributing to approximately $13 million of elevated fraudulent contract losses in its Acima segment during Q2 2026. The company implemented enhanced authentication, fraud detection and monitoring, and notified federal law enforcement. Filed under Item 8.01; company believes the incidents are not material.
Tagging rationale
ThreatUnknown
Filing does not attribute the incidents to a specific actor -> UNKNOWN.
MethodsData Exfil
Customer information and documents were 'obtained without authorization' by an external party -> DATA-EXFIL; no ransomware or system outage described.
AssetsPersonal DataCash Equivalent
Filing states 'certain non-sensitive customer information and other documents were obtained without authorization' and the information was used to generate ~$13M in fraudulent contract losses -> PERSONAL-DATA + CASH-EQUIVALENT.
EffectsFinancial FraudInfo Privacy Loss
Stolen information was 'used to facilitate fraudulent lease-to-own agreements, contributing to elevated fraudulent contract losses of approximately $13 million' -> FINANCIAL-FRAUD primary, with customer data compromise -> INFO-PRIVACY-LOSS.
Impact
Approximately $13 million in fraud losses in a single quarter with ongoing investigation -> $10-50M band -> score 3.
InsuranceNot disclosed
Filing makes no mention of insurance -> null.
Read the original SEC filing excerpt
Item 8.01 Other Events. Upbound Group, Inc. (the "Company") recently experienced cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization. In connection with certain such incidents, the Company believes the information was subsequently used to facilitate fraudulent lease-to-own agreements, contributing to elevated fraudulent contract losses of approximately $13 million in the Company's Acima segment during the second quarter of 2026. Upon identifying the data compromise, the Company promptly began implementing mitigation and remediation measures. These measures, implemented in coordination with external cybersecurity experts, include enhanced authentication controls, additional fraud detection and monitoring capabilities, and other security enhancements. The Company also notified federal law enforcement of the incidents. The Company's investigation of these incidents remains ongoing, and it will make any legal or regulatory notifications as appropriate based on its investigation findings. Based on the Company's current knowledge of the quantitative and qualitative facts and circumstances related to the incidents, the Company believes that the incidents are not material. Should any of the relevant facts and circumstances substantively change, the Company will reassess materiality considerations in accordance with Item 1.05 of Form 8-K.