Progressive Leasing ( 40 million Customers PII Data ) Listed by alphv Ransomware Group: Ransomware Claim — What’s Alleged & What To Do
The Progressive Leasing ( 40 million Customers PII Data ) Listed by alphv Ransomware Group (reported September 22, 2023) is an unverified claim; the data involved is undisclosed belonging to roughly unknown people. If you have an account with them, your information may now be circulating on the open web and with data brokers. Here’s exactly what happened, how to check if you were affected, and what to do next.
In September 2023, Progressive Leasing appeared on a listing associated with the alphv ransomware group, which claimed the company had been hit in a ransomware attack involving exfiltrated internal files and asserted that data tied to a very large customer base was involved. Public reporting does not confirm how many people were actually affected or exactly what personal details left the company’s control. For customers who use lease-to-own financing to buy merchandise, that uncertainty matters: lease-to-own providers routinely handle identity, contact, payment, and credit-related information, and any exposure of that material can create lasting practical risk even when full details remain unconfirmed.
What is known so far is limited to the group’s claim, the reported date of the listing, and a description of internal files taken in a ransomware incident. No independent public confirmation of scale, specific data fields, or notification status is included in the available record. People who have used Progressive Leasing still have reason to understand the claim, the actor behind it, and the concrete steps that reduce harm if their information was among what was taken.
What happened
According to the available record, Progressive Leasing was listed by the alphv ransomware group on or about September 22, 2023. The listing described a ransomware attack in which internal files were allegedly exfiltrated and framed the incident in terms of customer personally identifiable information at a very large scale. The number of people affected is recorded as unknown. Beyond the characterization of internal files taken in a ransomware attack, the public facts do not detail the intrusion method, the duration of unauthorized access, whether encryption was deployed alongside theft, or what specific systems were involved.
Ransomware incidents of this type typically involve unauthorized access, theft of data before or during disruption, and a public pressure campaign on a leak site. In this case, the leak-site appearance is a claim by the group rather than a verified inventory of what was stolen. No confirmed count of affected individuals, no itemized list of data elements, and no dollar figures or internal quotes appear in the facts provided. Readers should treat the headline assertion about tens of millions of customers’ PII as part of the group’s unverified listing unless and until the company or regulators publish corroborated detail.
Who is alphv?
Alphv, widely known in public reporting as BlackCat, is a ransomware operation that has functioned as a ransomware-as-a-service model. Affiliates gain access to victim environments, exfiltrate data, deploy encryptors in many cases, and use dedicated leak sites to name victims and threaten publication if demands are not met. The group has been associated with double-extortion tactics: pairing operational disruption with the threat of releasing stolen files to increase pressure on the organization.
Public documentation of alphv activity over recent years describes targeting across multiple sectors, use of custom ransomware written in modern languages, and negotiation channels that emphasize proof of theft. Law-enforcement actions and infrastructure disruptions have been reported against the brand at various times, yet listings under the name have continued to appear in open sources. None of that general history proves the accuracy of any single victim claim. For Progressive Leasing, the only incident-specific assertion in the record is that alphv listed the company and described exfiltrated internal files in a ransomware attack; those statements remain the group’s claims.
About Progressive Leasing
Progressive Leasing is described in the available summary as a leading provider of in-store, ecommerce, and app-based point-of-sale lease-to-own solutions. It offers payment options and flexible terms aimed at customers who may be credit-challenged and who want a path to merchandise ownership. The business sits under PROG Holdings, Inc., a fintech holding company headquartered in Salt Lake City, Utah, that provides consumer financial products and payment options.
Organizations in the lease-to-own and point-of-sale financing sector typically sit at the intersection of retail transactions and consumer credit. They collect and process information needed to approve leases, verify identity, arrange payments, service accounts, and manage collections. A breach claim against such a provider is consequential because the same data that makes lease decisions possible—identity attributes, contact details, financial and payment data, and account history—can be reused for fraud, social engineering, or account takeover if it is stolen. Even when a company serves customers through retail partners and digital channels, the central financing platform often holds concentrated stores of sensitive customer records.
The information in question
The facts name the exposed material as internal files exfiltrated in a ransomware attack. They do not publish a confirmed inventory of fields such as names, Social Security numbers, bank accounts, or full credit files. The alphv listing headline referred to customer PII at a scale of roughly forty million people; that figure is part of the group’s claim and is not recorded here as a verified affected-person count. The number of people affected remains unknown in the provided record.
Companies that offer lease-to-own and similar consumer financing commonly hold government identifiers, dates of birth, addresses, phone numbers, email addresses, income or employment information, payment card or bank details, lease contracts, and payment histories. They may also retain retailer or device data tied to transactions. Whether any or all of those categories were present in the files alphv claims to have taken has not been confirmed in the facts given. Until Progressive Leasing or official notices specify otherwise, the exact contents should be treated as unconfirmed, while the realistic possibility of sensitive consumer and account data remains the prudent working assumption for anyone who has applied for or held a lease.
What's at stake
For individuals, the primary risks are identity theft, new-account fraud, and targeted scams. If identifiers and contact data were taken, criminals can attempt to open credit lines, file false claims, or impersonate the company or a retailer in phishing messages that reference a real lease. Payment or banking details, if present, raise direct financial-fraud concerns. Even partial files—contract terms, balances, or merchandise descriptions—can make social-engineering attempts more convincing. These harms can unfold months after an incident, which is why monitoring and cautious handling of unexpected outreach remain useful even when a company has not yet issued a personalized notice.
For the organization, a ransomware event that includes claimed data theft brings operational, legal, and trust consequences: potential regulatory scrutiny in consumer finance, contractual obligations to retail partners, costs of investigation and customer support, and reputational damage among credit-challenged consumers who depend on lease-to-own access. None of those outcomes requires proving negligence; they follow from the sensitivity of the data such firms hold and from the public nature of leak-site pressure. Because the affected population size is unknown and the data types are only broadly described, both customers and the company face a period of incomplete information in which precaution is more useful than panic.
Were you affected?
If you have used Progressive Leasing—online, in-store, or through a retail partner—treat the alphv claim as a reason to tighten basic protections rather than as proof that your file was taken. Review bank and card statements for unfamiliar charges, consider a fraud alert or credit freeze through the major credit bureaus, and be skeptical of unsolicited calls or messages that demand payment or personal details while referencing a lease. Use unique passwords and multi-factor authentication on email and financial accounts so that a leaked password elsewhere is harder to reuse against you. Keep any official notice from the company if one arrives; it may describe specific data and any support offered.
You can also run a free exposure scan of your email address to check whether that address has already appeared in known breach datasets, which can help you prioritize password changes and monitoring. Public detail on this incident remains limited: the listing date, the ransomware-and-exfiltration framing, and the group’s unverified assertions are what the record supports. Stay alert to official updates from Progressive Leasing or PROG Holdings, and base further action on confirmed notices when they become available.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
QSI INC - Credit Cards & Transaction Processing Listed by alphv Ransomware GroupCosal is a company that distributes personal and confidential data of its customers and re Listed by alphv Ransomware GroupCredifiel was hacked and a lot of personal customer and financial information was stolen Listed by alphv Ransomware GroupWright Moore DeHart Dupuis & Hutchinson Listed by alphv Ransomware GroupLatest breaches
Publicly posted by alphv — unverified claim, pending independent verification
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.