Upbound Group Reports $13 Million in Fraudulent Acima Leases Following Cybersecurity Incident

The Upbound Group, a prominent fintech company specializing in financial solutions and lease-to-own (LTO) products, has disclosed a significant cybersecurity incident that resulted in approximately $13 million in fraudulent Acima leases. The company, formerly known as Rent-A-Center, revealed in a filing with the U.S. Securities and Exchange Commission (SEC) that unauthorized actors gained access to its systems, obtaining certain non-sensitive customer information and other documents. This pilfered data was subsequently exploited to perpetrate fraud within its Acima lease-to-own segment.
Background of the Breach and Fraudulent Activity
The incident, which came to light in Upbound Group’s recent SEC filing, points to a sophisticated cyberattack that compromised sensitive customer data. While the company has characterized the stolen information as "non-sensitive," the nature of its use in orchestrating lease-to-own fraud indicates a deeper understanding of Acima’s operational workflows by the threat actors. The stolen credentials or information were used to initiate fraudulent lease agreements through Acima’s platform, which facilitates lease-to-own payment options via third-party retailers and e-commerce sites.
Acima, a key brand under the Upbound Group umbrella, acts as an intermediary, enabling consumers to acquire goods from participating retailers through a lease-to-own model. In this fraudulent scheme, the attackers successfully leveraged the compromised data to secure goods from retailers, with Acima subsequently reimbursing these retailers for the merchandise. However, the fraudsters failed to fulfill their lease payment obligations, leaving Acima Group with substantial financial losses. The total estimated financial impact of this fraudulent activity has been pegged at around $13 million, primarily impacting the Acima segment during the second quarter of the current year.
Timeline and Remediation Efforts
While a precise date for the initial compromise has not been publicly disclosed, Upbound Group stated in its SEC filing that it initiated mitigation and remediation measures "immediately after detecting the hack." This suggests a swift response once the breach was identified. The company enlisted the assistance of external cybersecurity experts to fortify its defenses and address the vulnerabilities that led to the incident.
The implemented remediation measures are multi-faceted and aim to prevent future occurrences. These include:

- Enhanced Authentication Controls: Strengthening the security protocols around user access to prevent unauthorized entry into sensitive systems. This could involve implementing multi-factor authentication (MFA) or reviewing and tightening existing access permissions.
- Additional Fraud-Detection Mechanisms: Deploying more robust systems and algorithms to identify suspicious transaction patterns and flag potentially fraudulent activities in real-time. This is crucial given the nature of the attack, which exploited the existing lease-to-own infrastructure.
- Improved Monitoring: Increasing the vigilance of system monitoring to detect anomalous activities or potential security threats more effectively. This proactive approach is vital for early detection of ongoing or new attack attempts.
Furthermore, Upbound Group has taken the necessary step of notifying federal law enforcement authorities about the incident. The company has indicated that it is continuing its investigation and will implement further actions based on the evolving findings. This collaborative approach with law enforcement is standard practice in cases of significant cybercrime and financial fraud.
Upbound Group’s Business and the Acima Brand
Upbound Group, a publicly traded entity, operates under several well-known brands, including Acima Leasing, Rent-A-Center, Brigit, and Upbound Mexico. Its core business revolves around providing alternative financial solutions and lease-to-own products, catering to a significant segment of consumers who may not qualify for traditional credit. The Acima brand, specifically, plays a crucial role in this ecosystem by partnering with a wide network of retailers, both online and brick-and-mortar, to offer flexible payment options for consumers looking to acquire furniture, electronics, appliances, and other goods.
The lease-to-own model, while beneficial for many consumers, can be susceptible to fraud if not adequately secured. The process typically involves a customer selecting an item from a participating retailer, applying for a lease-to-own agreement through a company like Acima, and then making regular payments for the item with the option to own it outright after a specified period. The breach at Upbound Group highlights a critical vulnerability in this process, where stolen personal information can be used to impersonate legitimate customers and defraud both the leasing company and the retailers involved.
Financial Impact and Regulatory Scrutiny
The disclosed $13 million loss represents a notable financial setback for Upbound Group, particularly within its Acima segment. While the company has not provided specific details on the number of affected customers or retailers, the scale of the financial loss suggests a considerable operation by the perpetrators.
In its SEC filing, Upbound Group also provided a crucial piece of information regarding the potential impact on investor confidence. The company stated that evidence uncovered thus far "indicates that the cyberattack was not significant enough to affect investment decisions." This statement, likely made to comply with disclosure requirements and manage market perception, suggests that the financial loss, while substantial, is considered manageable within the company’s overall financial standing and does not fundamentally alter its business outlook from an investor’s perspective. However, the long-term implications for customer trust and the company’s reputation in the highly competitive fintech and alternative finance sector remain to be seen.
Broader Implications and Industry Concerns

This incident underscores the persistent and evolving threat of cybercrime targeting financial institutions and companies handling sensitive customer data. The ability of threat actors to exploit data for fraudulent lease-to-own agreements demonstrates a sophisticated understanding of financial mechanisms and a willingness to adapt their attack vectors.
The implications of this breach extend beyond Upbound Group:
- Retailer Vulnerability: Participating retailers are also indirectly affected, as they bear the initial cost of the goods provided to fraudulent lessees and may face disruptions in their sales channels if trust in the LTO system erodes.
- Consumer Confidence: Such incidents can erode consumer confidence in lease-to-own services, potentially impacting adoption rates and the overall perception of alternative finance providers. Consumers are increasingly concerned about the security of their personal information, and breaches can lead to hesitancy in engaging with services that require such data.
- Industry-Wide Security Standards: The breach serves as a stark reminder for the entire fintech and alternative finance industry to continuously review and enhance their cybersecurity measures. This includes not only protecting against external threats but also implementing robust internal controls and fraud prevention mechanisms. The increasing sophistication of cyberattacks necessitates a proactive and layered security approach.
Lack of Public Claims and Ongoing Investigation
As of the time of reporting, no ransomware groups or known data extortion actors have publicly claimed responsibility for the attack on Upbound Group. This is not uncommon, as some threat actors operate covertly to maximize their illicit gains without drawing attention. The absence of a public claim does not diminish the severity of the incident or the need for thorough investigation and remediation.
BleepingComputer has reached out to Upbound Group for further details regarding the incident, including the estimated number of affected customers and the specific types of non-sensitive data compromised. However, no response was received by the time of publication. The company’s ongoing investigation, in collaboration with federal law enforcement, will be critical in understanding the full scope of the breach, identifying the perpetrators, and further strengthening its defenses.
The incident at Upbound Group highlights a critical vulnerability in the lease-to-own sector and the broader landscape of alternative finance. As cyber threats continue to evolve, companies like Upbound Group must remain vigilant, investing heavily in robust cybersecurity infrastructure and proactive threat mitigation strategies to protect their customers, their operations, and their financial stability. The $13 million in fraudulent leases serves as a costly reminder of the ever-present risks in the digital economy.







