Upbound says hack caused $13 million in fraudulent Acima leases

A major fintech company, Upbound Group, has suffered a significant cyberattack that resulted in over $13 million in fraudulent lease agreements through its Acima platform. The attackers used stolen customer data to obtain goods and then failed to make payments, leaving retailers out of pocket.

The breach was made possible by unauthorized access to certain non-sensitive customer information and documents stored on Upbound’s systems. This sensitive data was then exploited to create fake lease-to-own agreements through the Acima platform. In these scams, customers were tricked into leasing goods without their knowledge or consent, with the attackers pocketing the profits.

Acima is a popular payment option for consumers who want to purchase goods on credit rather than upfront. Partner retailers and e-commerce sites offer Acima as an alternative financing solution, allowing customers to spread payments over time. However, in this case, the attackers used stolen data to create fake accounts and obtain goods through these agreements.

The full extent of the breach is still being investigated by Upbound’s cybersecurity experts and law enforcement authorities. The company has taken steps to mitigate the damage, including enhanced authentication controls, additional fraud-detection mechanisms, and improved monitoring. However, with no clear resolution in sight, it remains to be seen how this will affect consumer trust in the Acima platform.

This incident highlights a critical vulnerability in many online platforms: the reliance on customer data for smooth transactions. While companies like Upbound are taking steps to improve security, attacks can still occur through unauthorized access or exploitation of vulnerabilities. The fact that no ransomware group has publicly claimed responsibility suggests that this may be an opportunistic attack rather than part of a larger campaign.

For consumers and businesses alike, this serves as a stark reminder of the ongoing threat posed by cybercrime. As we rely increasingly on digital platforms for financial transactions, it is essential to prioritize cybersecurity measures, such as multifactor authentication and regular data backups. Only through vigilance can we hope to prevent similar breaches from occurring in the future.

In light of this incident, users of the Acima platform would be wise to review their account activity regularly and report any suspicious behavior to Upbound’s customer support team. Additionally, consumers should remain cautious when dealing with unfamiliar or unverified retailers offering lease-to-own agreements through online marketplaces.


Source: Bleeping Computer — 2026-07-22