DataBreachSearch.com

Did Upbound Group, Inc. have a data breach?

Answer

Yes. Upbound Group, Inc. reported a data breach to the Oregon Attorney General on September 28, 2026.

View the official filing

What the filing says

Reported to
Oregon Attorney General
Filing date
September 28, 2026
Breach date
July 3, 2026
People affected
Not stated in the filing

Information involved

  • Full Name
  • Social Security Number
  • Date of Birth
  • Financial Account Number
  • Routing Number
  • Mailing Address
  • Driver's License Number
  • Transaction History

In plain terms

Upbound Group, Inc. reported a data breach on September 28, 2026, stemming from an incident on July 3, 2026. The breach involved highly sensitive personal and financial information, raising concerns for affected individuals about potential identity theft and fraud.

Upbound Group, Inc. filed a data breach notification with Oregon authorities on September 28, 2026, disclosing an incident that occurred on July 3, 2026. The company, a prominent leader in lease-to-own and financial services, confirmed that customer data was compromised.

The breach type was unspecified, but it involved unauthorized access to sensitive personal information. Given Upbound Group's business model, which handles extensive consumer financial data, such incidents often involve vulnerabilities within network infrastructure or third-party vendor systems.

The exposed information includes Full Name, Social Security Number, Date of Birth, Financial Account Number, Routing Number, Mailing Address, Driver's License Number, and Transaction History. This combination of identifiers and financial details presents significant risks for those affected.

Individuals whose data was exposed face an elevated threat of identity theft, fraudulent credit applications opened in their name, and unauthorized withdrawals from their bank accounts. Cybercriminals can use this information to cause substantial financial harm.

To safeguard against potential misuse of their data, affected individuals should actively monitor their financial accounts and credit reports for any suspicious activity. Placing a fraud alert or freezing credit with the major credit bureaus are also widely recommended steps. Reviewing all account statements regularly can help detect unauthorized transactions promptly.

Other filings by Upbound Group, Inc.

Companies often file the same breach in several states. Each filing is listed separately.

Commonly recommended next steps

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Replace exposed ID documents

    Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Look up another company

Other breaches reported in Oregon

DataBreachSearch.com reports what was filed with state regulators. It is not legal advice, is not a law firm, and is not affiliated with any government agency or with Upbound Group, Inc..