DataBreachLegalCenter.com
MonitoringCalifornia AG filing · September 27, 2026

Upbound Group Confirms Data Exposure Affecting Consumer Information

Upbound Group, Inc. reported a data security incident in September 2026, impacting sensitive personal and financial data. If you received a notification, your information like Social Security Number and banking details may have been exposed. This creates potential risks for identity theft and financial fraud.

Received a Upbound Group, Inc. notification letter? Find out in minutes if you qualify for compensation.

Free case review
State
California
Breach date
July 3, 2026
Reported
September 27, 2026

What may have been exposed

  • Full Name
  • Social Security Number
  • Date of Birth
  • Financial Account Number
  • Routing Number
  • Mailing Address
  • Credit and Payment History
  • Driver License Number

Upbound Group, Inc., known for its lease-to-own retail and consumer services brands, formally reported a data security incident to California authorities on September 27, 2026. This notification confirms that an unauthorized party gained access to its network, potentially compromising sensitive consumer information. Receiving a letter from Upbound Group indicates your data may be among the affected records.

The exposed data categories include Full Name, Social Security Number, Date of Birth, Financial Account Number, Routing Number, Mailing Address, Credit and Payment History, and Driver License Number. This combination of identifying and financial details is particularly valuable to malicious actors. It could be used to facilitate identity theft, open fraudulent accounts, or target you with sophisticated scams.

As a company handling vast quantities of sensitive consumer data, Upbound Group, Inc. has an obligation under California law to safeguard this information. The occurrence of a data breach suggests that there may have been vulnerabilities in their security protocols. An ongoing investigation is monitoring the situation to determine the full extent and nature of the incident.

Your data breach notification letter from Upbound Group, Inc. is a formal acknowledgment that your private information was involved in this security event. This notice is a key document that establishes your standing to seek legal recourse. Even if you haven't yet experienced direct financial loss, the increased risk of future identity theft and the burden of monitoring your accounts can be recognized as harms.

Understanding your position after a data breach can be complex. We offer a free, no-obligation attorney case review to help clarify your options. This review allows you to discuss the specifics of your situation and learn about any potential steps you might take.

Received a Upbound Group, Inc. notification letter? Our legal team tracks every Upbound Group, Inc. data breach filing and offers a free case review. See the full Upbound Group, Inc. case file on DataBreachClassActions

What to do if you were affected

Based on the categories of information reported in this filing, these steps can help limit the risk of identity theft and fraud.

  • Freeze your credit

    Place a free credit freeze with Equifax, Experian, and TransUnion. A freeze blocks new accounts from being opened in your name and can be lifted anytime.

  • Watch your financial accounts

    Review bank and card statements for unfamiliar activity and turn on transaction alerts. Report anything you don't recognize to your bank right away.

  • Replace exposed ID documents

    Contact your state DMV or the issuing agency about replacing an exposed driver's license, passport, or government ID number.

  • Stay alert to targeted scams

    Be cautious of calls, texts, or emails that reference this breach. Legitimate organizations won't ask you to confirm sensitive details through an unsolicited message.

  • Keep your notification letter

    Save the notice you received. It documents that your information was involved and is often needed to enroll in any credit monitoring offered or to join a related legal claim.

Source: California Attorney General filing

Related data breach cases