Security News

Cybersecurity news aggregator

HIGH Attacks SC Media

Upbound Group reports $13 million in losses due to data breach and fraud

A data breach at Upbound Group's Acima segment allowed threat actors to steal customer information and documents, which were then used to fraudulently generate leases and obtain merchandise, resulting in $13 million in losses. The company is implementing enhanced authentication, fraud detection, and monitoring measures with the assistance of cybersecurity experts. No technical details regarding a specific vulnerability, CVSS score, affected software versions, or patches are provided in the source article.
Read Full Article →

Data Security , Identity , Privacy Upbound Group reports $13 million in losses due to data breach and fraud July 23, 2026 Share By SC Staff (Adobe Stock) Upbound Group, a fintech company, disclosed that a data breach allowed threat actors to steal customer information and documents, which were then used to commit fraud and generate approximately $13 million in fraudulent Acima leases. The company experienced cybersecurity incidents where certain non-sensitive customer information and other documents were obtained without authorization, according to a recent report by Bleeping Computer. The breach affected Upbound Group's Acima segment, a lease-to-own (LTO) provider. Threat actors exploited the stolen data to fraudulently obtain goods through Acima's system. Acima paid retailers for these items, but the fraudsters absconded with the merchandise and failed to make payments, leading to the $13 million financial loss in the second quarter. Upbound Group, formerly Rent-A-Center, is implementing mitigation and remediation measures, including enhanced authentication, fraud detection, and monitoring, with the assistance of cybersecurity experts. Federal law enforcement has been notified, and the company is continuing its investigation. No ransomware groups have claimed responsibility for the attack. Source: Bleeping Computer SC Staff Related Data Security Malicious ModHeader extension pulled from Chrome and Edge stores SC Staff July 15, 2026 Security researchers at Stripe OLT discovered that version 7.0.18 of ModHeader included a hidden spyware SDK. Data Security How to Build a Cloud, SaaS and AI Data Governance Program SC Media Editorial Intelligence, reviewed by Aparna Achanta July 14, 2026 Embed governance into the data movement process rather than applying governance after data has moved Data Security What Data Protection Actually Controls SC Media Editorial Intelligence, reviewed by Aparna Achanta July 14, 2026 Effective data protection determines whether stolen information is actually usable and how much business and regulatory damage an organization suffers after a breach Related Events Cybercast Beyond the Hype: The Cybersecurity Trends CISOs are Keeping an Eye on in 2026 On-Demand Event Cybercast Beyond the data perimeter: Why next-generation DSPM is the foundation for modern data security On-Demand Event Virtual Conference Securing the Future of Finance: Strategies to Counter Modern Cyber Threats On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Basic Authentication Bit Block Cipher Certificate-Based Authentication Cryptographic Algorithm or Hash Cryptographic Hash Functions Cyclic Redundancy Check (CRC) Data Aggregation Data Loss Prevention (DLP) Diffie-Hellman You can skip this ad in 5 seconds

Share this article