← All stories
● Covered by 2 sources · 2 reportsMedium impact2 neutral

Upbound Group discloses $13M fraud in Acima leases following data breach

🔄 Updated 71d ago — new reporting from SecurityWeek
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • Non-sensitive customer data was stolen from Upbound Group systems.
  • Stolen data facilitated $13 million in fraudulent Acima leases.
  • Fraudulent activity occurred in Q2 2026.
  • Upbound Group operates brands like Acima, Rent-A-Center, and Brigit.
  • Law enforcement and cybersecurity experts are involved.

Cybersecurity Incident Revealed

Upbound Group, a fintech company operating brands like Acima Leasing and Rent-A-Center, disclosed a cybersecurity incident. Threat actors obtained certain non-sensitive customer information and other documents without authorization from the company's systems. This disclosure was made in a filing with the U.S. Securities and Exchange Commission (SEC).

Fraudulent Lease-to-Own Agreements

The stolen information was subsequently used by threat actors to commit fraud within Upbound's lease-to-own agreements, specifically impacting its Acima segment. Acima provides lease-to-own payment options through third-party retailers and e-commerce platforms. The attackers used the compromised data to secure goods through Acima’s system under fraudulent agreements.

Acima paid participating retailers for these goods, but the fraudsters took the merchandise and did not fulfill the required lease payments. This activity led to financial losses totaling approximately $13 million for the Acima segment during the second quarter of this year.

Company Response and Mitigation

Upon detecting the hack, Upbound Group initiated immediate mitigation and remediation efforts. The company engaged external cybersecurity experts to assist in these measures. Actions taken include implementing enhanced authentication controls, deploying additional fraud-detection mechanisms, and improving monitoring capabilities.

Federal law enforcement authorities have been notified about the incident, and Upbound Group continues its investigation. The company stated it would take further action based on the investigation's findings.

Financial Impact and Ongoing Investigation

The $13 million loss represents the direct financial impact of the fraud on Upbound Group's Acima segment. Despite the significant financial loss, evidence uncovered so far indicates that the cyberattack is not expected to affect investment decisions. The investigation into the full scope and details of the incident is ongoing.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~34 min · 27 stories · Oct 02

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

How outlets covered it

Upbound Group, a consumer finance company, disclosed a data breach that led to approximately $13 million in fraudulent contract losses within its Acima segment during Q2 2026. The breach involved non-sensitive customer information, which was used to facilitate fraudulent lease-to-own agreements.

Upbound Group reported a cybersecurity incident where threat actors stole non-sensitive customer information and documents, leading to $13 million in fraudulent Acima lease-to-own agreements. The stolen data was used to obtain goods, resulting in financial losses for the company when fraudsters failed to make payments. Upbound has implemented enhanced security measures and notified federal law enforcement.