VYPR
breachPublished Jul 22, 2026· 1 source

Upbound Group Loses $13 Million to Fraudulent Acima Leases Following Data Breach

Fintech company Upbound Group disclosed a data breach that enabled threat actors to generate $13 million in fraudulent Acima leases, impacting its lease-to-own segment.

Upbound Group, a prominent fintech company, has revealed that a cybersecurity incident allowed threat actors to access its systems and subsequently generate approximately $13 million in fraudulent leases through its Acima segment. The breach, disclosed in a filing with the U.S. Securities and Exchange Commission (SEC), involved the unauthorized acquisition of certain non-sensitive customer information and other documents.

The stolen data was then exploited by the attackers to perpetrate fraud within Acima's lease-to-own agreements. Acima, which facilitates lease-to-own payment options for third-party retailers and e-commerce sites, would pay participating retailers for goods provided under these agreements. However, the fraudsters absconded with the merchandise without making the required lease payments, leading to the substantial financial losses for Upbound Group.

Upbound Group, formerly known as Rent-A-Center, operates a portfolio of brands including Acima Leasing, Rent-A-Center, Brigit, and Upbound Mexico, offering various financial solutions and lease-to-own products. The Acima segment, specifically, is designed to provide flexible payment options for consumers purchasing goods from partner retailers.

Immediately upon detecting the security incident, Upbound Group initiated mitigation and remediation efforts, enlisting the assistance of external cybersecurity experts. The company has since implemented enhanced authentication controls, bolstered fraud-detection mechanisms, and improved its monitoring capabilities to prevent further unauthorized access and fraudulent activity.

Federal law enforcement authorities have been notified of the breach, and Upbound Group is continuing its investigation into the full scope and impact of the incident. The company stated in its SEC filing that the cyberattack, based on current evidence, was not significant enough to warrant disclosure regarding its impact on investment decisions.

As of the disclosure, no ransomware groups or data extortion actors have publicly claimed responsibility for the attack on Upbound Group. The company has not yet provided details on the number of affected customers, and the specific method of initial access or data exfiltration remains under investigation.

This incident highlights the persistent risks associated with data breaches in the financial technology sector, where compromised customer information can be directly leveraged for financial fraud. The scale of the fraudulent leases underscores the sophisticated methods employed by threat actors to exploit sensitive data for monetary gain.

Synthesized by Vypr AI