Upbound Group

Upbound Group

Lease-to-own financing across retailers and customers

Overview

Upbound Group operates a family of lease-to-own and rent-to-own brands, including Acima Leasing and Rent-A-Center. It provides flexible financing options for durable goods by partnering with thousands of retailers to offer at-point-of-sale lease-to-own options. Customers can lease items such as furniture, appliances, electronics, and computers, with the option to purchase or return at any time. The company differentiates itself through a portfolio of brands and a broad network of retail partnerships, combining technology-driven lease solutions with physical locations to reach a wide customer base. Its goal is to elevate financial opportunity for all by expanding access to affordable, flexible payment options and improving financial inclusion.

About Upbound Group

Simplify's Rating
Why Upbound Group is rated
C+
Rated C on Competitive Edge
Rated B on Growth Potential
Rated C on Differentiation

Industries

Company Size

201-500

Company Stage

IPO

Headquarters

Texas

Founded

1973

Get referred to Upbound Group

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Q2 2026 free cash flow jumped to $84 million, boosting 2026 guidance to $250 million.
  • Acima’s charge-offs fell to 8.8%, showing tighter underwriting is working.
  • Brigit’s premium mix lifted ARPU to $14.30, expanding monetization without physical stores.

What critics are saying

  • Acima’s July 2026 breach caused $13 million fraudulent lease losses and law-enforcement scrutiny.
  • Rent-A-Center’s 69-store closures signal a shrinking legacy footprint and margin pressure.
  • If Acima fraud persists, Upbound’s underwriting credibility and lease-to-own economics deteriorate quickly.

What makes Upbound Group unique

  • Upbound combines Brigit fintech, Acima lease-to-own, and Rent-A-Center stores across channels.
  • Brigit grew 37% in Q2 2026, driven by 1.7 million paying users.
  • Amazon returns, Wayfair checkout, and Experian partnership extend Upbound’s distribution reach.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

401(k) Company Match

Health Savings Account/Flexible Spending Account

Tuition Reimbursement

Training Programs

Gym Membership

Stock Price

Company News

Yahoo Finance
Jul 30th, 2026
Upbound Group reports Q2 revenue of $1.2B with Brigit growing 37% and strong cash flow

Upbound Group reported second quarter 2026 results with consolidated revenue of approximately $1.2 billion, meeting guidance. The company's Brigit unit showed strong growth, with revenue rising 37% year-over-year to $71 million, driven by roughly 30% growth in paying subscribers to 1.7 million. Acima generated $604 million in revenue, down about 2.5% year-over-year, but improved its lease charge-off rate by 50 basis points to 8.8%. Rent-A-Center achieved $466 million in revenue with same-store sales increasing approximately 160 basis points. The company generated $123 million in net cash from operating activities and $84 million in free cash flow. For full-year 2026, Upbound narrowed its revenue guidance to $4.70–$4.85 billion whilst reaffirming adjusted EBITDA of $500–$535 million.

MarketBeat
Jul 30th, 2026
Upbound Group Q2 earnings call highlights.

Upbound Group Q2 earnings call highlights. July 30, 2026 Key points. * Upbound Group's second-quarter results were within guidance: revenue rose modestly to $1.2 billion, while adjusted EBITDA declined to $127 million and non-GAAP EPS fell about 4% to $1.70. Operating cash flow increased sharply to $123 million, and free cash flow improved to $84 million. * Acima faced cybersecurity-related fraud and weaker discretionary demand, contributing to an 11% decline in GMV and approximately $13 million in elevated fraudulent contract losses. However, tighter underwriting improved credit performance, with charge-offs falling to 8.8% and adjusted EBITDA rising 5%. * Upbound narrowed its full-year revenue outlook to $4.7 billion-$4.85 billion while reaffirming adjusted EBITDA and EPS guidance, but raised free cash flow guidance to approximately $250 million. Brigit remained a growth driver, with revenue up 37% and paying users up 30% year over year. * Interested in Upbound Group? Here are five stocks we like better. Upbound Group NASDAQ: UPBD reported second-quarter 2026 results that were within its guidance, as improved portfolio performance and cash generation helped offset pressure on consumer demand, particularly for discretionary durable goods. Chief Executive Officer Fahmi Karam said the company's risk management and underwriting actions supported cash flow, debt reduction and progress on strategic initiatives despite a challenging economic backdrop for non-prime consumers. Consolidated revenue totaled $1.2 billion, modestly higher than the prior year, while adjusted EBITDA declined year over year to $127 million. Non-GAAP diluted earnings per share were $1.70, down about 4% from the prior-year quarter. Operating cash flow rose sharply. Net cash provided by operating activities was $123 million, compared with $26 million a year earlier, while free cash flow was $84 million, compared with negative $10 million in the prior-year period. Cybersecurity incident pressures Acima GMV. Karam said the company experienced cybersecurity incidents during the second quarter in which certain non-sensitive customer information and other documents were obtained without authorization. The company believes some of the information was subsequently used to facilitate fraudulent lease-to-own agreements. The incidents resulted in approximately $13 million of elevated fraudulent contract losses in the Acima segment during the quarter. Upbound has begun remediation efforts, including enhanced authentication controls, additional fraud detection and monitoring capabilities, and other security improvements. The company also notified federal law enforcement. Karam said the investigation remains ongoing, but Upbound does not expect a material impact from the incidents. Acima's gross merchandise volume, or GMV, declined about 11% year over year to approximately $466 million, while revenue fell 2.5% to $604 million. Management attributed the decline to deliberate underwriting tightening, the cybersecurity incidents and weaker demand for discretionary categories such as furniture and appliances. Despite lower volume, Acima's credit results improved. Lease charge-offs declined 50 basis points year over year to 8.8%, while adjusted EBITDA rose about 5% to $98 million. The segment's adjusted EBITDA margin increased 117 basis points to 16.2%. Discover more American Consumer News Company Earnings Karam said the company is prioritizing risk-adjusted margin over volume in the current environment. He added that Acima has new merchant agreements in its pipeline and expects GMV to return to year-over-year growth during the fourth quarter. Acima's checkout button with Wayfair is now live, according to the company. Brigit growth continues. Financial wellness and liquidity platform Brigit posted revenue of $71 million, up 37% from a year earlier. Paying users reached approximately 1.7 million at quarter-end, an increase of about 30% year over year. Monthly average revenue per user increased 6.3% to $14.30, supported by a greater mix of premium-tier customers, marketplace engagement and optional expedited-transfer revenue. Brigit's net advance loss rate was approximately 3.6%, consistent with recent quarters, and it generated roughly $11.8 million of adjusted EBITDA. Chief Financial Officer Hal Khouri said the company increased advertising and marketing spending to support subscriber growth, and that returns on the investment remained positive based on customer lifetime value. Karam said demand for Brigit's products has exceeded expectations and the company may consider additional marketing investment later in the year. Brigit also entered a multiyear partnership with Experian in May to offer its earned wage access product to Experian Money Plus members. Karam said the relationship expands Brigit beyond its direct-to-consumer model and adds a new distribution and revenue channel. The company is also continuing a pilot of its line-of-credit product, which management said has seen strong demand. Rent-A-Center optimizes store base. Rent-A-Center recorded its third consecutive quarter of same-store sales growth, with same-store sales increasing 1.6% year over year. Segment revenue was $466 million, and average portfolio value per store rose approximately 3.5% from a year earlier. Lease charge-offs were approximately 5%, up 30 basis points year over year but within the company's expected range. Adjusted EBITDA fell about 8% to $63 million amid inflationary expenses and higher fixed costs. During the quarter, the company closed 69 underperforming Rent-A-Center stores and merged customer accounts into nearby locations. Karam said the initial optimization effort was intended to improve efficiency while limiting revenue disruption. He said the company will continue evaluating its store footprint, using digital capabilities and market-level operating models to improve profitability. Rent-A-Center has also completed deployment of its Amazon order pickup and returns partnership across approximately 1,500 corporate-owned locations. Karam said the program has driven increased store traffic and brand awareness, though the initiative is still in its early stages. Guidance narrowed as free cash flow outlook rises. Upbound narrowed its full-year revenue outlook to between $4.7 billion and $4.85 billion, reflecting second-quarter results, lower durable-goods demand and continued underwriting discipline. The company reaffirmed its adjusted EBITDA guidance of $500 million to $535 million and non-GAAP diluted EPS outlook of $4.00 to $4.35. * Full-year free cash flow guidance increased to approximately $250 million from $200 million. * Acima expects 2026 GMV and revenue to be flat to down low single digits year over year, with losses stabilizing below 9% for the year. * Brigit continues to expect annual revenue growth above 30%, with revenue of $265 million to $285 million and adjusted EBITDA of $50 million to $60 million. * Rent-A-Center expects full-year revenue to be flat to down low single digits, while adjusted EBITDA margin is expected to remain relatively flat from 2025. For the third quarter, Upbound expects revenue of $1.05 billion to $1.15 billion, adjusted EBITDA of $105 million to $115 million, and non-GAAP diluted EPS of $0.85 to $0.95. Management expects Acima GMV to improve sequentially but remain down low to mid-single digits year over year before returning to growth in the fourth quarter. The company ended the quarter with approximately $487 million of liquidity, net debt of about $1.3 billion and leverage of 2.6 times trailing-12-month adjusted EBITDA, down from 2.9 times at the end of 2025. Upbound paid a quarterly dividend of $0.39 per share, or approximately $23 million, during the quarter. About Upbound Group (NASDAQ:UPBD). Upbound Group, Inc leases household durable goods to customers on a lease-to-own basis in the United States, Puerto Rico, and Mexico. It operates through four segments: Rent-A-Center, Acima, Mexico, and Franchising. The company's brands, such as Rent-A-Center and Acima that facilitate consumer transactions across a range of store-based and virtual channels. It offers furniture comprising mattresses, tires, consumer electronics, appliances, tools, handbags, computers, smartphones, and accessories. This instant news alert was generated by narrative science technology and financial data from MarketBeat in order to provide readers with the fastest reporting and unbiased coverage. Please send any questions or comments about this story to [email protected]. Before you consider Upbound Group, you'll want to hear this. MarketBeat keeps track of Wall Street's top-rated and best performing research analysts and the stocks they recommend to their clients on a daily basis. MarketBeat has identified the five stocks that top analysts are quietly whispering to their clients to buy now before the broader market catches on... and Upbound Group wasn't on the list. While Upbound Group currently has a Moderate Buy rating among analysts, top-rated analysts believe these five stocks are better buys. Discover the 10 Best High-Yield Dividend Stocks for 2026 and secure reliable income in uncertain markets. Download the report now to identify top dividend payers and avoid common yield traps.

TEISS
Jul 24th, 2026
Upbound Group says data breach fueled $13 million in fraudulent leases.

Upbound Group says data breach fueled $13 million in fraudulent leases. Upbound Group, Inc., a Texas-based consumer finance company, disclosed that a recent breach of its computer systems led to millions of dollars in fraudulent contract losses tied to its lease-to-own business. In a filing with the U.S. Securities and Exchange Commission, Upbound said it experienced cybersecurity incidents in which non-sensitive customer information and other documents were obtained without authorization. The company said it believes that information was later used to set up fraudulent lease-to-own agreements, driving elevated fraudulent contract losses of approximately $13 million within its Acima segment during the second quarter of 2026. Upbound provides lease-to-own and flexible payment products through several brands, including Rent-A-Center, Acima, Brigit and Upbound Mexico. The company, formerly known as Rent-A-Center, operates as a significant participant in the alternative finance and rental industry. Its Acima brand extends lease-to-own payment arrangements through partnerships with third-party retailers and e-commerce platforms. According to the SEC filing, those behind the intrusion used the stolen customer data and documents to obtain merchandise through Acima's lease-to-own system by entering into fraudulent agreements. Acima paid participating retailers for the goods involved, but the individuals who obtained the merchandise did not make the required lease payments, producing losses of roughly $13 million. Upbound said it began mitigation and remediation work as soon as the intrusion was detected, working alongside outside cybersecurity specialists. Those efforts have included strengthening authentication controls, adding fraud-detection tools and expanding system monitoring. The company also notified federal law enforcement of the incidents. Upbound said its investigation remains ongoing and that it may take further action depending on what that investigation finds. As of the time of its SEC disclosure, the company said the evidence gathered so far indicates the incidents are not material. It remains unclear who carried out the intrusion. No known cybercrime group has listed Upbound on a data leak site, and no ransomware or extortion group has publicly claimed responsibility for the attack.

Canadian Cyber Security Journal
Jul 23rd, 2026
Cybersecurity daily brief - Thursday, July 23, 2026.

Cybersecurity daily brief - Thursday, July 23, 2026. Here are today's top cybersecurity stories for Thursday, July 23, 2026. Check Point CVE-2026-16232: Actively Exploited SmartConsole Zero-Day Gets CISA Deadline of July 25 Check Point Software has patched an authentication bypass in its SmartConsole GUI, tracked as CVE-2026-16232 (CVSS 9.1), after confirming active exploitation against management servers exposed to the internet. An unauthenticated attacker obtains a login token granting full administrator access to the Security Management Server, enabling security policy modification or firewall rule deletion without any credentials. CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a July 25, 2026 remediation deadline for federal agencies. BleepingComputer RefluXFS CVE-2026-64600: 9-Year-Old Linux XFS Race Condition Exposes 16.4 Million Systems to Root Takeover Qualys has disclosed RefluXFS, a race condition in the Linux kernel's XFS filesystem copy-on-write path dating back nine years, which lets any local user overwrite protected files and gain root privileges. The exploit leaves no kernel log output, survives reboots, and bypasses SELinux Enforcing mode, affecting RHEL, Oracle Linux, Amazon Linux, and Fedora Server across an estimated 16.4 million systems. The upstream kernel fix merged on July 16, 2026, and distributions are actively issuing backported patches. BleepingComputer Chaos Ransomware Deploys msaRAT Backdoor Hiding C2 Traffic Inside Chrome and Edge Browsers Cisco Talos has documented msaRAT, a Rust-based remote access trojan used by the Chaos ransomware group, which routes encrypted command-and-control traffic through headless Chrome or Edge processes via WebRTC and Cloudflare developer infrastructure. The malware controls the browser through the Chrome DevTools Protocol, making C2 traffic indistinguishable from ordinary browser cloud activity and invisible to most network-layer detection tools. Chaos operators gain initial access through spam floods, vishing, and Quick Assist abuse before deploying the backdoor. Cisco Talos JadeProx: China-Nexus Espionage Cluster Used TriBack Loader Against Governments and Hospitals Across Asia and Latin America Group-IB has published research on JadeProx, a China-nexus threat cluster uncovered when an exposed Alibaba Cloud server in Singapore was found holding operational data, including a previously undocumented Windows loader called TriBack Loader. Confirmed intrusions include a Vietnamese public hospital's medical imaging system, Malaysia's Ministry of Foreign Affairs, and a spear-phishing package targeting the National Congress of Honduras. The cluster used Chinese offensive tooling including iox, Neo-reGeorg, suo5, nuclei, and fscan for tunneling, pivoting, and mass reconnaissance. The Hacker News Upbound Group Says Acima Breach Led to $13 Million in Fraudulent Lease-to-Own Agreements Upbound Group, parent company of lease-to-own service Acima, disclosed a data breach in which stolen customer records were used to generate approximately $13 million in fraudulent lease agreements during Q2 2026. Attackers obtained customer information without authorization and placed fake lease-to-own orders, with Acima paying out merchandise to fraudsters who then disappeared without making payments. The company has notified federal law enforcement and implemented enhanced authentication controls and fraud-detection mechanisms. BleepingComputer South Korea Discloses 10-Month Diplomatic Academy Breach Exposing Data of Up to 10,000 Foreign Ministry Personnel South Korea has disclosed a data breach at the Korea National Diplomatic Academy lasting approximately ten months from April 2025 to February 2026, in which attackers exploited a zero-day vulnerability to access personal data of up to 10,000 current and former Ministry of Foreign Affairs employees, including overseas diplomats. Compromised records include names, user IDs, email addresses, encrypted passwords, positions, and departmental affiliations, though no sensitive identification numbers or internal government systems were accessed. South Korea's National Intelligence Service detected the breach in February 2026, and no confirmed misuse has been reported. BleepingComputer GitHub Actions Weaponized to Exploit cPanel CVE-2026-41940 Authentication Bypass at Scale Across Hosting Infrastructure Attackers compromised a PHP developer's GitHub account and injected 583 malicious GitHub Actions workflow files across ten Packagist packages between July 12 and 13, 2026, turning the PHP ecosystem into distributed scanning and exploitation infrastructure. Each workflow launches a GitHub-hosted runner, downloads an architecture-specific payload, and targets exposed cPanel and WHM servers through CVE-2026-41940, a critical authentication bypass, to harvest server credentials and administrative secrets. Internet-facing hosting environments running unpatched cPanel and WHM installations are the primary targets. The Hacker News Researchers Expose SharedRoot: Claude Cowork Sandbox Escape Lets Attackers Access Host Mac and Windows Filesystems Security researchers have disclosed SharedRoot, a sandbox escape vulnerability in Anthropic's Claude Cowork, which chains exploitation of CVE-2026-46331 in the agent's guest Linux kernel to break out of the VM and read or write files across the host Mac filesystem as the logged-in desktop user. A separate Windows variant exploits design flaws in the CoworkVMService RPC interface to achieve root-level command execution inside the Hyper-V-isolated Ubuntu VM. Anthropic has patched both variants. The Hacker News Adobe Patches HermeticReader CVE-2026-48294: Flaw in 329-Million-Install Acrobat Extension Exposed WhatsApp Web Chats Adobe has patched CVE-2026-48294 in its Acrobat Chrome extension, a flaw allowing a malicious website to inject a form into WhatsApp Web, capture the live chat body, and submit rendered messages, contact names, and conversation previews to an attacker-controlled server. The attack required no malware, no stolen credentials, and no WhatsApp vulnerability - a victim simply visiting a malicious page while signed into WhatsApp Web with the affected extension installed was sufficient. The extension has approximately 329 million installs, and Adobe released a patch within one weekend of responsible disclosure. SecurityWeek Theori Finds 434 Exploitable Vulnerabilities in 28 AI-Generated Applications Theori has published research on vibe-coded applications built across multiple AI models and development environments, identifying 434 verified exploitable security vulnerabilities after runtime testing and source-code review. The most common issues were insufficient rate limiting, insecure direct object references (IDOR), server-side request forgery (SSRF), and directory traversal, with modern AI models producing fewer SQL injection flaws but consistently missing authorization controls and secrets management. Five models from Anthropic and OpenAI were used across both greenfield and brownfield development scenarios. SecurityWeek Stay tuned for today's in-depth analysis posts. Enjoy this article? Don't forget to share.

CloudLink Tech
Jul 23rd, 2026
Upbound: Data breach led to $13M fraud in Acima segment.

Upbound: Data breach led to $13M fraud in Acima segment. Upbound Group says a recent data breach caused about $13 million in fraudulent lease-to-own contract losses in its Acima segment in Q2 2026. Upbound Group Inc., a Texas-based consumer finance company, reported a cybersecurity incident that led to roughly $13 million in fraudulent lease-to-own contract losses in its Acima segment during the second quarter of 2026, according to an SEC filing. The filing states attackers obtained non-sensitive customer information and other documents that were subsequently used to open fraudulent lease-to-own agreements, contributing to the losses in the Acima business. Upbound notified law enforcement and retained external cybersecurity experts to strengthen its systems. The company says its investigation is ongoing and that, at the time of the SEC disclosure, it did not view the incidents as material to the business overall. The filing did not name any perpetrators and noted there were no public claims on known cybercrime leak sites when the disclosure was made. Upbound did not detail whether it has made remedial payments to affected customers, whether customers will receive direct notifications beyond the SEC filing, whether ransom demands were involved, or whether all compromised access points have been fully secured. A newly launched tracker, the Hacker in a Hoodie (HIH) Index, aims to catalog material data breaches to help security teams and policymakers monitor incidents. Forensic work will be required to determine precisely how the fraud was carried out and whether additional customer protections or system changes are needed. Upbound operates lease-to-own and flexible payment services under brands including Rent-A-Center, Acima and Brigit.

Recently Posted Jobs

Sign up to get curated job recommendations

Upbound Group is Hiring for 46 Jobs on Simplify!

Find jobs on Simplify and start your career today

Don't see your dream role? Check out thousands of other roles on Simplify. Browse all jobs →