Upbound says hack caused $13 million in fraudulent Acima leases

2026-07-23T01:23:27Z7fcb901e927e529ec20af4eae90f2ba431fb2350a2de2476f688cacf98b24134
AI-securityCISACVE-2026-50522actively-exploitedcredential-stuffingdata-breachend-of-lifeextortionmalware-distributionnation-state-sensitivephishing-as-a-serviceprivacyransomwaresupply-chainvulnerability

What happened

Multiple high-impact incidents and active threats reported: a critical Microsoft SharePoint RCE (CVE-2026-50522) is being actively exploited to steal machine keys; CISA ordered urgent patching for an actively exploited Langflow RCE; the Upbound breach was abused to create $13M in fraudulent Acima leases; South Korea disclosed a 10-month breach of the National Diplomatic Academy affecting current and former MFA employees and diplomats worldwide; Swiss rail supplier platform was targeted with a ~$12.3M ransom demand (Everest gang); large malware distribution and fraud campaigns continue (FakeGit

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
7fcb901e927e529ec20af4eae90f2ba431fb2350a2de2476f688cacf98b24134
Enrichment time
2026-07-23T01:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Upbound says hack caused $13 million in fraudulent Acima leases · Baitaphish