GoFirm
Back to Blog
Case Studies·3 min read

Stolen documents opened $13 million in fraudulent leases at Acima. Nobody confirmed who was signing

By GoFirm

On 21 July 2026, Upbound Group, Inc. (Upbound), the Plano, Texas-based financial services company behind Acima Leasing, Rent-A-Center and Brigit, disclosed in a filing with the US Securities and Exchange Commission that it had suffered a cybersecurity incident involving customer data and documents obtained without authorisation. No ransomware gang or extortion group has claimed responsibility, and Upbound has not said how the data was taken, from which system, or how many customers were affected. What the company has confirmed is what happened to the data once it was out.

According to the filing, the stolen customer information and supporting documents were used to open fraudulent lease-to-own agreements through Acima's platform. Acima's business model lets a shopper walk out of a participating retailer with goods immediately, while Acima pays the retailer in full upfront and collects instalments from the customer over the following months. Anyone holding a stolen customer's documents, name, and personal details had everything needed to open a new agreement as if they were that person.

Acima paid retailers for goods against agreements that were never legitimate. The company disclosed that this activity contributed to approximately $13 million in elevated fraudulent contract losses in the Acima segment during the second quarter of 2026 alone. Whoever ran the scheme did not need to breach Acima's core systems a second time, move money directly, or negotiate a ransom. They needed a convincing set of someone else's documents and one successful application.

The incident sits inside a pattern GoFirm has tracked across dozens of cases this year: stolen identity data is no longer used only for resale on a leak site. It is increasingly used directly, to trigger a real financial transaction that a company then processes as routine business. A lease-to-own approval, a wire transfer, a credential reset, an account opening: each is a high-impact action, and each executed here without anyone confirming that the person behind the request was who the paperwork claimed.

Upbound is not a company that under-invested in security. It runs fraud detection, monitoring, and underwriting checks that most retailers its size do not have, and it moved quickly to add stronger authentication once the losses surfaced. Those defences were not weak by conventional standards. They were built to flag anomalies after an application had already entered the system. None of them sat at the one moment that actually mattered: the instant Acima approved the agreement and committed to pay a retailer, using someone else's identity.

Approving a new lease-to-own agreement is an execution event. Before Acima commits to pay a retailer and opens an account in a customer's name, GoFirm sends a confirmation request to that named customer's own registered device, asking for a biometric confirmation that they, and not someone holding their stolen documents, are the one opening the account. If no confirmation arrives, the agreement does not execute and the payment does not go out.

A stolen set of documents, however complete or convincing, cannot produce that confirmation on the real customer's device. The execution boundary holds regardless of how genuine the paperwork appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence
. Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Toulas, B. 2026. Upbound says hack caused $13 million in fraudulent Acima leases. BleepingComputer, 22 July 2026.
2. Upbound Group, Inc. 2026. Form 8-K: Other Events. U.S. Securities and Exchange Commission, 21 July 2026.
3. StockTitan. 2026. Upbound Group (NASDAQ: UPBD) cyber incident drives $13M Acima fraud loss. StockTitan, 22 July 2026.

Share this article