
The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases.
In a filing with the U.S. Securities and Exchange Commission (SEC), the company says that it “experienced cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization.”
The threat actor used the information to commit fraud in lease-to-own agreements, resulting in financial losses of about $13 million in the Acima segment in the second quarter of this year.
Upbound Group, formerly known as Rent-A-Center, provides financial solutions and lease-to-own (LTO) products. It is an important player in the alternative finance and rental sector that operates the Acima Leasing, Rent-A-Center, Brigit, and Upbound Mexico brands.
Acima provides lease-to-own payment options through third-party retailers and e-commerce sites.
According to the SEC filing, the attacker used stolen customer data and documents to obtain goods through Acima’s lease-to-own system under fraudulent agreements.
Acima paid the participating retailers for those goods, but the fraudsters took the merchandise and failed to make the required lease payments, resulting in approximately $13 million in losses.
The company says that immediately after detecting the hack, it began implementing mitigation and remediation measures with the help of external cybersecurity experts.
These measures include enhanced authentication controls, additional fraud-detection mechanisms, and improved monitoring.
Moreover, federal law enforcement authorities were notified accordingly. Upbound continues to investigate the incident and will take additional action depending on the findings.
Evidence uncovered so far indicates that the cyberattack was not significant enough to affect investment decisions.
BleepingComputer has contacted Upbound to request more details about the incident, such as the number of affected customers, but we did not receive a reply by publishing time.
Currently, no ransomware groups or data extortion threat actors have publicly claimed the attack on Upbound.
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.


