Hackers Steal Data, Cause $13 Million in Fraudulent Leases for Upbound Group
Criminals use stolen customer data from Upbound Group to commit $13 million in fraud through lease-to-own agreements.

Key points
- Hackers stole data and caused $13 million in losses for Upbound Group in Q2 2023.
- Upbound Group revealed this in a U.S. Securities and Exchange Commission (SEC) filing.
- The attackers used customer data to create fraudulent lease agreements through Acima.
- The company has taken steps to improve security and involve federal law enforcement.
Upbound Group, a major player in financial solutions and lease-to-own services, recently suffered a significant data breach. Hackers stole customer data and documents, then used them to set up fraudulent lease agreements, costing the company about $13 million.
According to a filing with the U.S. Securities and Exchange Commission (SEC), Upbound Group, formerly Rent-A-Center, experienced a cyberattack that compromised non-sensitive customer information. This data was used to commit fraud in their Acima segment in the second quarter of 2023.
Acima, a brand operated by Upbound Group, offers lease-to-own payment options through various retailers and e-commerce sites. The hackers used the stolen data to fraudulently acquire goods through Acima's system. The goods were paid for by Acima, but the criminals kept the merchandise and did not fulfill the lease payments.
Upbound Group stated that they detected the breach quickly and have since partnered with external cybersecurity experts to address the situation. They have introduced stronger authentication controls, better fraud-detection mechanisms, and enhanced monitoring systems. Federal law enforcement has also been informed.
The investigation into the incident is still ongoing, but initial findings suggest the breach was not severe enough to impact investment decisions. Upbound Group continues to review the situation and may take further action based on new findings.
How did the hackers get in?
The hackers accessed Upbound Group's systems and stole customer data, which they then used to create false lease agreements through Acima. The precise method of entry is not publicly detailed, but the company has focused on improving security controls and monitoring to prevent future incidents.
Currently, no ransomware groups or data extortion criminals have claimed responsibility for the attack. To date, Upbound Group has not responded to requests for more detailed information on the breach, including how many customers were affected.
For customers concerned about potential fraud, it is wise to monitor financial statements and alert your bank to any unauthorized transactions. This proactive approach can help detect fraud early and minimize potential losses.



