Upbound Group Data Breach Investigation

Upbound Group Inc reported a cybersecurity incident involving files stored in cloud applications, with regulatory incident data indicating that names and Social Security numbers may have been involved. The publicly available sample notice redacts the recipient-specific data field, so each person’s notice should be reviewed carefully. Strauss Borrelli PLLC is investigating the incident and its potential impact on affected individuals. If you received a notice, you may fill out the secure contact form on this page to help verify potential claim eligibility.

Key Facts at a Glance

  • Entity Involved: Upbound Group Inc
  • Incident Type: Unauthorized access to files stored in cloud applications
  • Date of Incident: July 3, 2026 to July 6, 2026
  • Discovery Date: July 13, 2026
  • Official Notice Date: September 23, 2026
  • Exposed Information: Names and Social Security numbers were identified in the supplied regulatory incident data; the public sample notice redacts the recipient-specific field
  • Affected Population: Under investigation or not publicly disclosed

What Happened?

According to a regulatory notice dated September 23, 2026, Upbound Group Inc learned of a cybersecurity incident on July 13, 2026. The company reported that an unauthorized third party gained access to certain computer files stored in cloud applications and obtained files between July 3 and July 6, 2026. A related California Attorney General portal entry was publicly listed on September 26, 2026.

Upbound stated that it began an investigation with assistance from a cybersecurity expert and implemented containment, remediation, and security-enhancement measures. The investigation reportedly concluded that files containing personal information associated with certain individuals were affected. The available filing does not disclose how the unauthorized party initially gained access, how many people were affected, or whether the information has been misused. Accordingly, the confirmed public details remain limited to the company’s reported findings and the information included in regulatory records.

What Information Was Exposed?

The structured regulatory information supplied for this incident identifies names and Social Security numbers as data that may have been involved. However, the public sample notification letter uses a placeholder where the affected recipient’s specific information would ordinarily appear. The exact combination of information involved for any individual therefore should be confirmed by reviewing that person’s notice.

Names combined with Social Security numbers can create risks of identity theft, fraudulent credit or loan applications, and impersonation. Because Upbound operates in financial services, affected individuals also should watch for account-verification texts, unauthorized password-reset attempts, wire-transfer requests, and callers pretending to investigate suspicious financial activity. The filing does not establish that any such misuse has occurred.

What Should You Do Next?

  1. Review your notice and enroll in available monitoring: Upbound reported offering eligible recipients one year of complimentary Experian IdentityWorks credit monitoring. Follow only the instructions in your personal letter, keep the activation code private, and note the stated enrollment deadline of December 31, 2026.
  2. Consider a credit freeze or fraud alert: A freeze can make it harder for someone to open new credit in your name. Freezes must be placed separately with Equifax, Experian, and TransUnion. A fraud alert can be requested through one bureau, which generally informs the others.
  3. Check credit reports and financial accounts: Review your credit files through AnnualCreditReport.com and inspect bank, credit-card, lending, and payment accounts for unfamiliar inquiries or transactions. Report suspicious activity promptly to the relevant institution.
  4. Be cautious about financial impersonation: Do not provide credentials, verification codes, or payment information in response to unexpected calls, emails, or texts. Independently contact the institution using a trusted telephone number before acting on a password-reset, loan, or wire-transfer request.
  5. Preserve relevant records: Keep the notification letter, envelope, monitoring enrollment confirmation, suspicious messages, credit reports, and documentation of any losses or time spent responding. These materials may help with disputes, identity-theft reports, or a legal review.

Your Legal Rights

People whose information was involved may have rights under state data-breach, privacy, consumer-protection, or negligence laws, depending on where they live and the circumstances of the incident. Potential issues may include whether reasonable safeguards were used, whether notice was provided as required, and whether an individual experienced identity theft, fraudulent charges, credit problems, lost time, or other legally recognized harm.

Consumers also generally may place or lift a credit freeze without charge, dispute inaccurate credit-report information, and submit an identity-theft report if misuse occurs. Available claims and deadlines vary by state, and receiving a notice does not automatically establish eligibility for compensation. This general information is not individualized legal advice.

Why Hire Strauss Borrelli PLLC?

The firm investigates cybersecurity and privacy incidents to determine what information may have been affected, what protections were provided, and whether impacted individuals may have viable claims. A confidential review can help recipients understand the notice, preserve useful records, and evaluate potential options under applicable law. No result can be guaranteed, and each person’s circumstances require an individual assessment.

If you received a breach notification letter from Upbound Group Inc:

We would like to speak with you about your rights and potential legal remedies in response to this data breach. Please fill out the form, below, or contact us at 872.263.1100 or sam@straussborrelli.com.

Data Breach Website Blog Form

Contact Us

Learn about your legal rights

Name
Terms & Conditions and Privacy Policy

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

Contact Us Now

Data Breach Website Blog Form

What can you do if you were impacted by a data breach?

If you were impacted by a data breach, you may consider taking the following steps to protect your personal information.

  1. Carefully review the breach notice and retain a copy;
  2. Enroll in any free credit monitoring services provided by the company;
  3. Change passwords and security questions for online accounts;
  4. Regularly review account statements for signs of fraud or unauthorized activity;
  5. Monitor credit reports for signs of identity theft; and
  6. Contact a credit bureau(s) to request a temporary fraud alert.

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

One Magnificent Mile
980 N Michigan Avenue, Suite 1610
Chicago, Illinois 60611

Phone: 872.263.1100
Toll Free: 866.748.6220

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.
PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY

©2026 STRAUSS BORRELLI PLLC. ALL RIGHTS RESERVED. ATTORNEY ADVERTISING.

PRIVACY POLICY  |  TERMS & CONDITIONS  |  COOKIE POLICY