"Experienced cybersecurity incidents in which certain non-sensitive customer information and other documents were obtained without authorization," the company's SEC filing states — and those stolen records have been used to generate roughly $13 million in fraudulent lease obligations, Upbound Group says.
Upbound Group disclosure and brands affected
In a Securities and Exchange Commission filing, Upbound Group — the financial-services company formerly known as Rent‑A‑Center — reported a cybersecurity incident that resulted in unauthorized access to customer information and documents. The company operates several consumer-facing brands, including Acima Leasing, Rent‑A‑Center, Brigit, and Upbound Mexico; the fraudulent activity was tied to Acima's lease‑to‑own (LTO) business.
How attackers converted stolen data into $13 million of Acima leases
According to the filing, threat actors used the stolen customer data and documents to complete lease‑to‑own agreements through Acima's system. Acima paid participating retailers for the merchandise provided under those agreements; the attackers then took the goods and did not make the required lease payments. Upbound attributes approximately $13 million in losses in Acima to that scheme during the company’s second fiscal quarter.
Technical and investigative steps reported by the company
Upbound says it moved immediately to contain and remediate the incident with help from external cybersecurity experts. The filing lists specific countermeasures already put in place: enhanced authentication controls, additional fraud‑detection mechanisms, and improved monitoring. Federal law enforcement authorities were notified, and the company says it continues to investigate and will take further action depending on what investigators uncover.
Retailers, Acima customers, and security teams: who this hits and how they may respond
- Acima customers: People whose records were taken may see fraudulent lease applications tied to their data; the filing does not specify how many customers were affected. Customers will likely need to monitor accounts and communications tied to Acima leases while Upbound's investigation continues.
- Participating retailers: Retail partners received payment from Acima for goods obtained through the fraudulent leases, but those goods were removed by fraudsters. Retailers may face inventory and chargeback complications and will want clarity from Acima on recovery and fraud‑prevention changes.
- Security teams and fraud investigators: Upbound’s deployment of added authentication, fraud‑detection rules, and monitoring reflects the operational focus many security teams take after credential and document misuse. The company’s engagement of external specialists and notification of federal law enforcement are steps security leaders will note as standard parts of an escalating response.
Financial framing and unanswered operational details
Upbound quantifies the immediate financial toll on Acima at about $13 million for the quarter in question and says available evidence indicates the cyberattack was not significant enough to affect investment decisions. The filing does not provide a customer‑count or a detailed timeline of when the unauthorized access began and was stopped. BleepingComputer contacted Upbound for additional details, including the number of affected customers, but had not received a reply by publishing time. No ransomware groups or data‑extortion actors have publicly claimed responsibility for the incident.
The sequence laid out in the filing — stolen customer documents used to open LTO agreements, Acima's payment to retailers, removal of merchandise by fraudsters, and subsequent nonpayment — underscores a specific fraud vector for lease‑to‑own platforms: data misuse to create apparently legitimate contracts. Upbound’s next steps, according to its filing, will follow the findings of the ongoing investigation and law‑enforcement coordination.
The original story: https://www.bleepingcomputer.com/news/security/upbound-says-hack-caused-13-million-in-fraudulent-acima-leases/
