Quick Summary
AllegedExecutive Summary
Acima, a financial services company operating in the United States, has been identified as a victim on the dark web portal of the IAH6477 ransomware group. The listing, dated August 20, 2026, was detected by SOCRadar’s Dark Web Monitoring service. Acima functions as a lease-to-own platform, facilitating consumer purchases of furniture, electronics, and appliances through retail partners across the U.S. This incident marks Acima as one of the relatively few U.S. financial services entities to be targeted by the IAH6477 group. In the 60 days preceding this listing, IAH6477 claimed a total of three other victims, suggesting a potentially newer or more selective threat actor. The group’s targeting appears to focus on the Technology, Financial Services, and Retail & E-Commerce sectors, with a concentration of victims in the United States. Previous listings from IAH6477 within this period include Regency Centers and other commercial organizations based in the U.S. Given Acima’s role as a consumer-facing financial platform that manages a significant volume of customer financial data, it represents a particularly sensitive target.
Technical Analysis
SOCRadar’s analysis of infostealer telemetry data for the acima.com domain revealed a substantial exposure, with 25 records identified. These records primarily targeted Acima’s customer-facing portals, including customer.acima.com, portal.acima.com, and associated authentication subdomains. The majority of the associated usernames were consumer email addresses or numeric identifiers, consistent with customer account compromise. However, a single record featured a username pattern that suggested a corporate or internal account, indicating that the exposure might not be exclusively limited to customer-side access. The most recent records in this dataset were dated August 20, 2026. For ransomware operations, credentials harvested by infostealers are a recognized method for initial access. Threat actors or initial access brokers frequently source these credentials from underground marketplaces, validate them, and then use them to access VPNs or remote access portals to deploy ransomware. While the primary observed exposure relates to customer portals, the presence of at least one credential formatted like a corporate account necessitates further scrutiny. Security teams should investigate internal employee access originating from Acima’s customer portal infrastructure to ascertain if any accounts with elevated privileges were compromised within this dataset. Given the findings, it is recommended that CTI teams continue monitoring dark web and stealer-log feeds for any further indicators related to Acima. Proactive credential hygiene checks, including password rotation and multi-factor authentication review for all accounts, are advised. Particular attention should be paid to auditing access logs for Acima’s customer portal infrastructure to identify any potential misuse of compromised corporate credentials.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.