Fintech firm Upbound Group has disclosed a serious cybersecurity incident where hackers accessed sensitive data, leading to the generation of $13 million in fraudulent Acima leases.
In a recent filing with the U.S. Securities and Exchange Commission, the company stated, “We have experienced a cybersecurity incident in which certain non-confidential customer information and other documents were obtained without authorization.”
The hackers exploited this information to execute fraudulent lease-to-own contracts, resulting in significant financial losses for Upbound’s Acima division during the second quarter of the year.
Upbound Group, previously known as Rent-A-Center, specializes in financial solutions and lease-to-own (LTO) products. It operates several well-known brands including Acima Leasing, Rent-A-Center, Brigit, and Upbound Mexico within the alternative finance and rental sectors.
Acima provides lease-to-own payment options through both third-party retailers and e-commerce platforms.
According to the SEC filing, attackers utilized the stolen customer data to fraudulently secure goods via Acima’s lease-to-own system.
While Acima compensated participating retailers for these goods, the fraudsters failed to fulfill lease payment obligations, resulting in total losses nearing $13 million.
Upon detecting the breach, Upbound promptly initiated mitigation and remediation efforts, enlisting the help of external cybersecurity experts.
These proactive measures include enhanced authentication protocols, advanced fraud detection systems, and rigorous monitoring practices.
Moreover, federal law enforcement agencies have been informed of the breach. Upbound is conducting a thorough investigation into the incident and plans to implement additional measures based on its findings.
Current indications suggest that the cyberattack has not significantly impacted investment decision-making.
BleepingComputer reached out to Upbound for further details about the incident, including the number of affected customers, but had not received a response at the time of this publication.
As of now, there are no claims from ransomware groups or other data extortion entities regarding attacks on Upbound.
Security teams document only 54% of successful attacks, issuing warnings for just 14%. The remainder moves unnoticed through the environment.
Picus’ whitepaper details how to rigorously test your SIEM and EDR rules using breach and attack simulations to detect threats effectively.
Source: www.bleepingcomputer.com




