Upbound reports $13 million loss after stolen data enabled fraudulent Acima leases

Upbound Group says attackers used information taken during a cybersecurity incident to create fraudulent lease-to-own agreements, causing approximately $13 million in losses at its Acima business duri...

Upbound Group says attackers used information taken during a cybersecurity incident to create fraudulent lease-to-own agreements, causing approximately $13 million in losses at its Acima business during the second quarter of 2026.

In a filing with the U.S. Securities and Exchange Commission, the company said unauthorized parties obtained certain non-sensitive customer information and other documents. The stolen material was then allegedly used to apply for Acima leases and acquire merchandise through participating retailers and online merchants.

Under Acima’s business model, the company pays retailers for goods obtained through approved lease-to-own arrangements. In the fraudulent transactions, however, the perpetrators took the merchandise and did not make the required payments, leaving Acima responsible for the resulting financial impact.

Upbound, formerly known as Rent-A-Center, operates several consumer finance and lease-to-own brands, including Acima Leasing, Rent-A-Center, Brigit and Upbound Mexico. Acima offers payment options through third-party retailers and e-commerce platforms.

Investigation and response

The company said it began containment and remediation efforts as soon as it identified the incident. With assistance from outside cybersecurity specialists, Upbound has introduced stronger authentication requirements, expanded fraud-detection capabilities and increased monitoring of relevant systems and transactions.

Federal law enforcement agencies have also been notified. Upbound said its investigation remains active and that additional measures may follow as more information becomes available. Based on evidence reviewed so far, the company does not believe the incident was significant enough to influence investment decisions.

Upbound has not disclosed how many customers were affected or provided further technical details about the intrusion. No ransomware operation or extortion group had publicly claimed responsibility for the incident at the time of reporting.