DataBreachCaseFile.com
MonitoringOregon AG filing · September 28, 2026

Upbound Group, Inc. Reports Data Breach to Oregon Regulators

Upbound Group, Inc., a financial services company, reported an unspecified data breach to Oregon authorities on September 28, 2026. The incident, which occurred on July 3, 2026, exposed sensitive customer information including Social Security Numbers and financial account details. This exposure creates potential risks of identity theft and financial fraud for affected individuals.

State
Oregon
Breach date
July 3, 2026
Reported
September 28, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Financial Account Number
  • Routing Number
  • Mailing Address
  • Driver's License Number
  • Transaction History

Upbound Group, Inc., a prominent company in the lease-to-own and financial services sector, reported a data security incident to Oregon regulators on September 28, 2026. The company's filing indicates that the breach occurred on July 3, 2026, though the specific type of breach was not detailed.

The public filing specifies that the data exposed includes Full Name, Social Security Number, Date of Birth, Financial Account Number, Routing Number, Mailing Address, Driver's License Number, and Transaction History. Such information is often collected by companies like Upbound Group due to the nature of their business operations, which involve evaluating creditworthiness and processing financial transactions.

While the filing did not specify the number of individuals affected or the exact method of compromise, incidents involving this scope of data exposure can lead to significant risks for those impacted. Unauthorized access to personal and financial identifiers can enable various forms of fraud and identity theft.

Individuals who believe they may be affected by this breach should take steps to monitor their personal and financial accounts. Regularly reviewing bank statements, credit card activity, and explanations of benefits for any unauthorized transactions or suspicious activity is recommended. It is also advisable to obtain free credit reports from the three major credit bureaus and check them for any unfamiliar accounts or inquiries.

Consider placing a fraud alert on your credit files, which makes it harder for identity thieves to open new accounts in your name. For a stronger measure, a security freeze can restrict access to your credit report altogether. Be wary of unsolicited communications, as exposed data can be used in phishing or social engineering schemes to trick individuals into revealing more information.

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Replace exposed ID documents

    Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: Oregon Attorney General filing

Related data breach cases