Upbound Group says a cyberattack against its systems led to around $13 million in losses after criminals used stolen data to create fraudulent Acima lease-to-own agreements.
The fintech company disclosed the incident in a filing with the US Securities and Exchange Commission. Upbound said an unauthorised party obtained certain non-sensitive customer information and other documents from its systems.
The attackers then allegedly used the information to obtain goods through Acima’s lease-to-own platform. Acima paid participating retailers for the merchandise, but the fraudsters failed to make the required payments.
Stolen Data Used for Lease Fraud
Upbound said the fraudulent activity affected its Acima segment during the second quarter of 2026.
Acima offers lease-to-own payment options through third-party retailers and e-commerce websites. Customers can use the service to obtain products and make payments over time.
According to Upbound, the threat actors used stolen customer information and documents to create fraudulent lease agreements. The criminals then acquired goods through the platform.
Acima paid the partner retailers as normal. However, the people behind the fraudulent agreements kept the merchandise and did not make the expected lease payments.
As a result, Upbound recorded financial losses of approximately $13 million.
Upbound Starts Incident Response Measures
Upbound said it began mitigation and remediation work immediately after discovering the incident.
The company has brought in external cybersecurity experts to support the investigation and response. It has also introduced stronger authentication controls, additional fraud-detection tools and improved monitoring.
Federal law enforcement authorities have received notification about the attack. Upbound said it will take further action as the investigation develops.
The company has not disclosed how many customers may have had information exposed. It also has not specified what documents the attackers obtained.
Company Says Breach Is Not Material
Upbound said the information available so far does not indicate that the cyberattack is material to investors.
In other words, the company does not currently believe the incident is significant enough to affect investment decisions. However, the investigation remains ongoing, and the final impact could change if new evidence emerges.
No ransomware group or data-extortion operation has publicly claimed responsibility for the Upbound data breach.
Acima Is Part of Upbound’s Finance Portfolio
Upbound Group, formerly known as Rent-A-Center, operates several alternative-finance and lease-to-own brands.
Its portfolio includes Acima Leasing, Rent-A-Center, Brigit and Upbound Mexico. Acima is a major part of the group’s business, offering lease-to-own agreements through retail partners and online stores.
The Upbound data breach shows how stolen customer records can fuel fraud beyond identity theft. When criminals can use personal data and supporting documents to open financial agreements, businesses may face direct losses before the fraud is detected.


0 responses to “Upbound Data Breach Linked to $13M in Fraudulent Acima Leases”