ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Upbound Group says data breach fueled $13 million in fraudulent leases

Upbound Group, Inc., a Texas-based consumer finance company, disclosed that a recent breach of its computer systems led to millions of dollars in fraudulent contract losses tied to its lease-to-own business.


In a filing with the U.S. Securities and Exchange Commission, Upbound said it experienced cybersecurity incidents in which non-sensitive customer information and other documents were obtained without authorization. The company said it believes that information was later used to set up fraudulent lease-to-own agreements, driving elevated fraudulent contract losses of approximately $13 million within its Acima segment during the second quarter of 2026.


Upbound provides lease-to-own and flexible payment products through several brands, including Rent-A-Center, Acima, Brigit and Upbound Mexico. The company, formerly known as Rent-A-Center, operates as a significant participant in the alternative finance and rental industry. Its Acima brand extends lease-to-own payment arrangements through partnerships with third-party retailers and e-commerce platforms.


According to the SEC filing, those behind the intrusion used the stolen customer data and documents to obtain merchandise through Acima’s lease-to-own system by entering into fraudulent agreements. Acima paid participating retailers for the goods involved, but the individuals who obtained the merchandise did not make the required lease payments, producing losses of roughly $13 million.


Upbound said it began mitigation and remediation work as soon as the intrusion was detected, working alongside outside cybersecurity specialists. Those efforts have included strengthening authentication controls, adding fraud-detection tools and expanding system monitoring. The company also notified federal law enforcement of the incidents.


Upbound said its investigation remains ongoing and that it may take further action depending on what that investigation finds. As of the time of its SEC disclosure, the company said the evidence gathered so far indicates the incidents are not material.


It remains unclear who carried out the intrusion. No known cybercrime group has listed Upbound on a data leak site, and no ransomware or extortion group has publicly claimed responsibility for the attack.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543