On July 21–22, 2026, Upbound Group (the lease-to-own company formerly known as Rent-A-Center) told the SEC that cybersecurity incidents let attackers steal certain customer information—and then turn that data into roughly $13 million in fraudulent Acima leases.
That is not a dark-web dump story. It is identity theft converted into merchandise: retailers got paid, fraudsters walked with goods, and Acima ate the unpaid leases.
What Upbound disclosed
Per the company’s Form 8-K and coverage by BleepingComputer, unauthorized parties obtained “certain non-sensitive customer information and other documents.” Attackers used that material to open fraudulent lease-to-own agreements in the Acima segment during the second quarter of 2026.
Upbound said Acima paid participating retailers for the goods; the fraudsters took the merchandise and did not make required lease payments, producing about $13 million in losses. The company added authentication and fraud-detection controls, notified federal law enforcement, and continues investigating. It framed the incident as not significant enough to affect investment decisions—while still filing an 8-K.
Upbound did not publish how many customers’ records were taken. No ransomware brand publicly claimed the intrusion at initial reporting.
What “non-sensitive” still enables
Lease-to-own fraud does not always need full Social Security numbers. Names, addresses, contact details, and supporting documents are enough to spoof approvals when controls are weak. If you are an Acima or Rent-A-Center customer, treat unexpected lease confirmations, delivery texts, or credit-check alerts as hostile until verified in the official app or by phone.
Fraud rings that start with one LTO brand often spray the same identity packet across competitors. Expect copycat attempts at other rent-to-own and BNPL desks through the fall.
Who should care
Acima customers, retailers that originate Acima leases, credit unions and banks seeing sudden furniture/electronics inquiries, and other LTO platforms watching this playbook. Security teams should correlate lease-origination anomalies with recent credential stuffing against customer portals.
Action items
- Review Acima / Upbound account activity for leases you did not open.
- Ignore unexpected “lease approved” or “ID re-verify” links; use the official app.
- Consider a credit freeze if you receive an individual notice listing more sensitive fields.
- Retail partners: tighten in-store identity checks for Acima originations.
- Report suspected fraudulent leases to Upbound and local police promptly—speed matters for chargeback windows.
Canonical record
Upbound Acima fraud cyber incidents. Sources: SEC 8-K, BleepingComputer.