Upbound hack leads to $13M in fraudulent Acima leases

▼ Summary
– Upbound Group disclosed that threat actors stole non-sensitive customer information and documents from its systems, using the data to commit fraud.
– The fraud resulted in $13 million in losses in the Acima lease-to-own segment during the second quarter of this year.
– The attackers used stolen data to create fraudulent lease agreements, obtaining goods from retailers without making payments.
– Upbound implemented mitigation measures including enhanced authentication, fraud-detection mechanisms, and improved monitoring, and notified federal law enforcement.
– No ransomware group or data extortion actor has publicly claimed responsibility for the attack, and the incident was not deemed significant enough to affect investment decisions.
Upbound Group, a fintech company operating in the lease-to-own space, has disclosed a cybersecurity breach that resulted in $13 million in fraudulent leases through its Acima brand. The incident, detailed in a filing with the U.S. Securities and Exchange Commission (SEC), involved threat actors stealing non-sensitive customer information and other documents from the company’s systems.
According to the SEC filing, the attackers used the stolen data to create fraudulent lease-to-own agreements, specifically targeting the Acima segment during the second quarter of this year. Acima, which provides lease-to-own payment options through third-party retailers and e-commerce sites, paid the participating retailers for the goods obtained under these fake agreements. However, the fraudsters took the merchandise and defaulted on the required lease payments, leading to the $13 million loss.
Upbound Group, formerly known as Rent-A-Center, is a key player in the alternative finance and rental sector. It operates several brands, including Acima Leasing, Rent-A-Center, Brigit, and Upbound Mexico. The company stated that upon detecting the hack, it immediately initiated mitigation and remediation measures with the help of external cybersecurity experts. These steps include enhanced authentication controls, additional fraud-detection mechanisms, and improved monitoring of its systems.
The company also notified federal law enforcement authorities about the breach. Upbound continues to investigate the incident and will take further action based on the findings. So far, evidence suggests that the cyberattack was not significant enough to affect investment decisions, according to the company.
BleepingComputer reached out to Upbound for additional details, such as the number of affected customers, but did not receive a response by the time of publication. As of now, no ransomware groups or data extortion threat actors have publicly claimed responsibility for the attack on Upbound.
(Source: BleepingComputer)




