Breach taxonomy
Summary
Upbound Group disclosed cybersecurity incidents in which non-sensitive customer information and other documents were obtained without authorization and subsequently used to facilitate fraudulent lease-to-own agreements, contributing to approximately $13 million of elevated fraudulent contract losses in its Acima segment during Q2 2026. The company implemented enhanced authentication, fraud detection and monitoring, and notified federal law enforcement. Filed under Item 8.01; company believes the incidents are not material.
Tagging rationale
ThreatUnknown
Filing does not attribute the incidents to a specific actor -> UNKNOWN.
MethodsData Exfil
Customer information and documents were 'obtained without authorization' by an external party -> DATA-EXFIL; no ransomware or system outage described.