LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › United Seating and Mobility LLC dba Numotion Data Breach Notice (Indiana Attorney General)

MEDIUM severityConfirmedHow we verify

United Seating and Mobility LLC dba Numotion Data Breach Notice (Indiana Attorney General): What Was Exposed & What To Do

RBRecent Breaches Breach Intelligence·May 22, 2026
United Seating and Mobility LLC dba Numotion Data Breach Notice (Indiana Attorney General)

Occurred February 01, 2026 · publicly disclosed May 22, 2026. Approximately 24 people affected.

MEDIUM
Severity
24
People affected
1
Data types exposed
May 22, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

United Seating and Mobility LLC, doing business as Numotion, has disclosed a data breach affecting 24 individuals. The breach occurred on February 1, 2026, and was reported to the Indiana Attorney General on May 22, 2026. If you received services from Numotion, check for any notices and consider placing a fraud alert or credit freeze.

Severity & verification
MEDIUM severityConfirmed
Data types not itemised.
Corroborated by an official disclosure or a verified breach feed.
Check your exposure
24 accounts were exposed here. We can’t confirm any single incident against the sources we search — but we can show you every leak and listing tied to your email. 15-sec check, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Inside the incident

United Seating and Mobility LLC, doing business as Numotion, notified Indiana residents of a data breach in a filing reported to the Indiana Attorney General on May 22, 2026. According to that filing, the underlying incident itself occurred on February 1, 2026. The notice states that 24 people were affected. Public detail beyond these points remains limited.

The disclosure identifies the exposed material only as personal information, without further breakdown of specific fields, systems involved, or the technical path of the incident. No additional counts, file volumes, dollar figures, or forensic findings appear in the reported summary. Attribution to any particular threat group is absent from the available record, and the method of unauthorized access or exposure has not been described in the filing.

What is known, therefore, is narrow but concrete: a company operating under the Numotion name experienced an incident dated February 1, 2026, later reported the matter to Indiana authorities on May 22, 2026, and indicated that personal information belonging to 24 individuals was involved. Timing between the incident date and the regulatory filing spans roughly three and a half months; the reasons for that interval are not stated in the public notice.

How a breach like this happens

Incidents that lead to notices of this kind typically begin with some form of unauthorized access to systems or records that hold personal data. Common pathways, in general terms and not specific to this case, include compromised credentials, phishing that yields remote access, misconfigured cloud storage, vulnerable remote-access services, or malware that enables data collection. Once inside an environment, an attacker or unauthorized process may locate files, databases, or backups containing names, contact details, identifiers, or other personal records.

Organizations often discover such events through internal monitoring, employee reports, law-enforcement tips, or external notifications. After discovery, standard practice includes containment, assessment of what records were touched, and determination of whether notification laws in relevant states require formal notices to residents and regulators. The precise sequence in any single case can vary widely; when a filing does not describe the intrusion method, as here, the public record simply leaves that step undisclosed.

No claim is made that any of these general patterns occurred at Numotion. They are background only, offered so readers understand the ordinary lifecycle of events that produce attorney-general breach notices.

About United Seating and Mobility LLC dba Numotion

United Seating and Mobility LLC operates under the trade name Numotion. Companies in this sector supply complex rehabilitation technology—custom wheelchairs, seating systems, mobility devices, and related clinical and fitting services—to people with disabilities and mobility impairments. Their work routinely involves coordination with clinicians, insurers, and patients, which means they typically maintain records that include personal identifiers, contact information, health-related details necessary for device fitting and billing, and sometimes insurance or payment data.

A breach affecting even a modest number of individuals at such an organization carries weight because the data is often more sensitive than ordinary retail or marketing lists. Mobility and seating providers sit at the intersection of healthcare support and durable medical equipment; the information they hold can reveal medical conditions, living situations, and financial arrangements tied to care. That context explains why state notification statutes treat personal information held by these firms as material when it is exposed.

Nothing in the Indiana filing asserts negligence or assigns fault. The notice simply records that an incident occurred and that a defined set of residents was affected.

The information in question

The breach notification names the exposed data only as “personal information.” No further itemization—such as Social Security numbers, dates of birth, medical record numbers, addresses, or financial account details—appears in the reported summary. Because the exact data elements remain unconfirmed beyond that broad label, it is not possible to state with certainty which specific fields were involved.

Organizations that provide seating and mobility equipment commonly hold, in the ordinary course of business, names, addresses, telephone numbers, dates of birth, insurance identifiers, clinical notes related to device needs, and billing information. Whether any or all of those categories were present in the February 1, 2026 incident is not established by the public filing. Readers should treat the contents as limited to what the notice itself states: personal information affecting 24 people.

What's at stake

For the individuals counted in the notice, the primary risks are the ordinary consequences of personal information leaving controlled custody. Depending on what fields were actually present, those consequences can include unwanted contact, attempts at identity fraud, or social-engineering efforts that reference real personal details. Even when the absolute number of affected people is small—here, 24—the impact on each person is individual and can be lasting if the data is later misused.

For the organization, the stakes include regulatory follow-up, the cost of investigation and notification, potential civil claims, and reputational effects among patients, clinicians, and referral partners who rely on the firm for sensitive equipment and services. Because the filing provides no dollar amounts or remediation details, those organizational consequences remain outside the confirmed public record.

The limited scale reported does not eliminate concern; it simply bounds the known population. People outside the 24 may still wish to verify whether their own information has appeared in other, unrelated breach corpora.

If your data was in this breach

If you believe you are one of the individuals notified, begin by reading any letter or email you received from the company carefully and retaining it. Consider placing a free fraud alert or credit freeze with the major consumer reporting agencies, monitoring account statements and explanation-of-benefits forms for unfamiliar activity, and being cautious of unexpected calls or messages that reference your mobility equipment or medical needs. If a specific type of identifier was listed in your personal notice, take the corresponding protective steps for that identifier.

You can also run a free exposure scan of your email address to check whether that address has already surfaced in other known breach data sets. Doing so does not confirm or deny inclusion in this particular Numotion incident, but it can surface additional exposures that warrant attention. Keep records of any steps you take, and consult official state or federal consumer resources if you encounter clear signs of misuse.

Public information on this matter is drawn solely from the Indiana Attorney General filing dated May 22, 2026, which places the incident on February 1, 2026, and reports 24 people affected with personal information involved. Further technical or forensic detail has not been released in that notice.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Company

CompanyUnited Seating and Mobility LLC dba Numotion security record
60/100
DoxxScan™ · Moderate doxx risk
D+ 56Weak record

1 reported incident on record.

See United Seating and Mobility LLC dba Numotion’s full breach history →
RelatedMore incidents at United Seating and Mobility LLC dba Numotion

More recent breaches

Deer Management Co. LLC dba Bessemer Venture Partners Data Breach Notice (Indiana Attorney General)September 30, 2026Midvale Indemnity and American Family Connect Insurance Data Breach Notice (Indiana Attorney General)September 30, 2026Republic National Distributing Company LLC Data Breach Notice (Indiana Attorney General)September 25, 2026Financial Administrative Support Services Data Breach Notice (Indiana Attorney General)September 25, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the United Seating and Mobility LLC dba Numotion Data Breach Notice (Indiana Attorney General) →

Source: Indiana Attorney General breach notification

Verified breach

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram