Upbound Group, Inc. Reports Data Breach to Oregon Regulators
Upbound Group, Inc., a financial services company, reported an unspecified data breach to Oregon authorities on September 28, 2026. The incident, which occurred on July 3, 2026, exposed sensitive customer information including Social Security Numbers and financial account details. This exposure creates potential risks of identity theft and financial fraud for affected individuals.
- State
- Oregon
- Breach date
- July 3, 2026
- Reported
- September 28, 2026
What may have been exposed
- Full Name
- Social Security Number
- Date of Birth
- Financial Account Number
- Routing Number
- Mailing Address
- Driver's License Number
- Transaction History
Upbound Group, Inc., a prominent company in the lease-to-own and financial services sector, reported a data security incident to Oregon regulators on September 28, 2026. The company's filing indicates that the breach occurred on July 3, 2026, though the specific type of breach was not detailed.
The public filing specifies that the data exposed includes Full Name, Social Security Number, Date of Birth, Financial Account Number, Routing Number, Mailing Address, Driver's License Number, and Transaction History. Such information is often collected by companies like Upbound Group due to the nature of their business operations, which involve evaluating creditworthiness and processing financial transactions.
While the filing did not specify the number of individuals affected or the exact method of compromise, incidents involving this scope of data exposure can lead to significant risks for those impacted. Unauthorized access to personal and financial identifiers can enable various forms of fraud and identity theft.
Individuals who believe they may be affected by this breach should take steps to monitor their personal and financial accounts. Regularly reviewing bank statements, credit card activity, and explanations of benefits for any unauthorized transactions or suspicious activity is recommended. It is also advisable to obtain free credit reports from the three major credit bureaus and check them for any unfamiliar accounts or inquiries.
Consider placing a fraud alert on your credit files, which makes it harder for identity thieves to open new accounts in your name. For a stronger measure, a security freeze can restrict access to your credit report altogether. Be wary of unsolicited communications, as exposed data can be used in phishing or social engineering schemes to trick individuals into revealing more information.
What to do if you were affected
Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.
Freeze your credit
Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.
Watch your financial accounts
Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.
Replace exposed ID documents
Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.
Stay alert to targeted scams
Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.
Keep your notification letter
Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.
Source: Oregon Attorney General filing
Related data breach cases
- OneMain Financial
- MedImpact Healthcare Systems, Inc.
- Call-On-Doc, Inc.
- Ridgeway Pharmacy Ltd
- IDScan.net
- Kaniksu Community Health
- Craneware, Inc.
- See's Candies - Corporate Office
- Cornerstone Staffing Solutions, Inc.
- zHealth, Inc.
- Greenberg Traurig, LLP (“GT”)
- Northwest Paper Box Manufacturers
- Quatrro Business Support Services, Inc.
- ASOS US Sales LLC