DataBreachCaseFile.com
MonitoringCalifornia AG filing · September 27, 2026

Upbound Group Reports 2026 Data Breach Exposing Extensive Personal Data

Upbound Group, Inc. filed a report in September 2026 confirming an unauthorized network compromise detected in July 2026. This incident exposed sensitive personal information, including Full Name, Social Security Number, Date of Birth, and Financial Account Number, creating significant risks for affected individuals.

State
California
Breach date
July 3, 2026
Reported
September 27, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Financial Account Number
  • Routing Number
  • Mailing Address
  • Credit and Payment History
  • Driver License Number

Upbound Group, Inc., a consumer services and lease-to-own retail holding company, formally reported a data security incident to the California Attorney General on September 27, 2026. This filing confirms an unauthorized compromise of its network environment, which was initially detected on July 3, 2026.

While the exact method of attack is under ongoing investigation, the nature of Upbound Group's business involves handling extensive sensitive personal and financial consumer data for applications, credit evaluations, and payment processing. The company's public filing indicates this incident involved unauthorized access to systems holding such information.

The exposed data categories include Full Name, Social Security Number, Date of Birth, Financial Account Number, Routing Number, Mailing Address, Credit and Payment History, and Driver License Number. The compromise of these details creates significant risks for affected individuals, including potential identity theft and various forms of financial fraud.

Individuals who receive notification about this incident are advised to take protective measures. These include placing a fraud alert or security freeze on their credit reports with all three major credit bureaus. It is also recommended to regularly review financial account statements and credit reports for any suspicious activity and to be vigilant against unsolicited communications requesting personal information.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Replace exposed ID documents

    Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases