Upbound Group, the fintech company known for its Rent-A-Center and Acima Leasing brands, has disclosed in a filing with the U.S. Securities and Exchange Commission that a cybersecurity incident led to $13 million in fraudulent lease-to-own transactions.

The company said threat actors gained unauthorized access to “certain non-sensitive customer information and other documents” from its systems. That stolen data was then used to commit fraud within Acima’s lease-to-own program, which lets consumers acquire goods from third-party retailers and e-commerce sites through installment agreements.

According to the filing, attackers used the compromised customer records and documents to obtain goods under fraudulent lease agreements. Acima paid participating retailers for the merchandise as it normally would, but the fraudsters took possession of the goods and never made the required lease payments. Upbound says this resulted in approximately $13 million in losses within the Acima segment during the second quarter of this year.

Response and remediation

Upbound Group, formerly Rent-A-Center, operates Acima Leasing, Rent-A-Center, Brigit, and Upbound Mexico. Acima specifically provides lease-to-own payment options at checkout for third-party merchants.

The company says it began mitigation and remediation efforts immediately after detecting the intrusion, working with outside cybersecurity experts. Measures put in place include enhanced authentication controls, stronger fraud-detection mechanisms, and improved monitoring across its systems. Upbound also notified federal law enforcement.

The investigation into the incident is ongoing, and the company says it may take further action depending on what additional findings surface. Upbound stated that, based on evidence gathered so far, the incident is not material enough to affect investment decisions.

No claims from extortion groups

Upbound has not disclosed how many customers were affected by the exposure of their information, and no ransomware or data extortion group has publicly claimed responsibility for the breach. The company has not yet detailed exactly how the attackers initially gained access to its systems.

Security professionals monitoring fintech and alternative lending platforms should note that this incident illustrates how stolen personal data, even when described as “non-sensitive,” can be weaponized directly for financial fraud through legitimate business processes such as lease origination, rather than solely through identity theft or resale on dark web markets.