Fintech firm Upbound Group revealed that attackers who stole knowledge from its techniques used it to generate $13 million in Acima leases.
“Now we have skilled a cybersecurity incident by which sure non-confidential buyer info and different paperwork have been obtained with out authorization,” the corporate mentioned in a submitting with the U.S. Securities and Alternate Fee.
The attackers used that info to commit fraud on lease-to-own contracts, leading to roughly $13 million in monetary losses for the Acima division within the second quarter of this 12 months.
Upbound Group, previously referred to as Hire-A-Heart, gives monetary options and lease-to-own (LTO) merchandise. The corporate is a key participant within the different finance and rental sector, working the Acima Leasing, Hire-A-Heart, Brigit and Upbound Mexico manufacturers.
Acima gives lease-to-own fee choices by way of third-party retailers and e-commerce websites.
In line with SEC filings, the attackers used stolen buyer knowledge and paperwork to acquire items by way of Acima’s lease-to-own system below fraudulent contracts.
Acima paid collaborating retailers for these things, however the fraudsters took the gadgets and did not make the required lease funds, leading to a lack of roughly $13 million.
The corporate mentioned that as quickly because it detected the hack, it started deploying mitigation and remediation measures with the assistance of exterior cybersecurity consultants.
These measures embrace enhanced authentication controls, extra fraud detection mechanisms, and enhanced monitoring.
As well as, federal legislation enforcement authorities have been additionally notified accordingly. Upbound continues to analyze the incident and can take extra motion relying on the result.
The proof that has emerged thus far means that the cyberattack was not important sufficient to affect funding choices.
BleepingComputer contacted Upbound and requested for extra particulars in regards to the incident, together with the variety of clients affected, however didn’t obtain a response by the point of publication.
At present, no ransomware teams or knowledge extortion actors are publicly claiming assaults on Upbound.

Safety groups doc 54% of profitable assaults and challenge a warning on solely 14%. The remaining strikes invisibly by way of the surroundings.
Picus’ whitepaper exhibits how you can take a look at your SIEM and EDR guidelines in breach and assault simulations to make sure threats go undetected.
Get the white paper
