United Seating and Mobility LLC dba Numotion Data Breach Notice (Massachusetts Attorney General): What Was Exposed & What To Do
United Seating and Mobility LLC dba Numotion has disclosed a data breach affecting 28 individuals, with credit or debit card numbers exposed. The breach was reported to the Massachusetts Attorney General on May 22, 2026. Anyone who received services from the company should review their financial statements and consider placing a fraud alert or credit freeze.
In a threat landscape where payment data remains a steady target for criminals who monetize card details through fraud and resale, even smaller-scale incidents can leave lasting practical problems for the people involved. United Seating and Mobility LLC, doing business as Numotion, has notified Massachusetts residents of a data breach in a filing reported to the Massachusetts Office of Consumer Affairs on May 22, 2026. Public detail from that notice indicates that credit or debit card numbers were among the information exposed, and that 28 people were affected.
The disclosure matters because card numbers are directly usable for unauthorized charges and related identity misuse. For a company that supplies complex rehabilitation technology and mobility equipment, any compromise of payment information also raises ordinary questions about how customer financial data was handled and what follow-up steps are available to those named in the notice.
Breaking down the breach
According to the Massachusetts Attorney General–related filing, United Seating and Mobility LLC dba Numotion submitted a data breach notice reported on May 22, 2026. The notice states that credit or debit card numbers were among the information exposed. The filing lists 28 people as affected.
Public detail is limited beyond those points. The available summary does not describe how the incident was discovered, whether systems were accessed remotely or through another vector, how long any unauthorized access lasted, or whether other categories of personal information were involved. No dollar loss figures, forensic timeline, or technical method are included in the facts provided in the notice summary. What is established is the organization named, the reporting date to Massachusetts authorities, the count of people affected, and the explicit inclusion of credit or debit card numbers among exposed data types.
How a breach like this happens
Incidents that result in exposure of payment card numbers often follow familiar patterns, though none of those patterns is confirmed for this specific case. In general terms, card data can be obtained when attackers gain access to systems that process or store transactions, when malware is introduced into point-of-sale or billing environments, when credentials for administrative accounts are phished or reused, or when files and backups containing payment details are left reachable without adequate controls. Criminals may also exploit unpatched software, misconfigured cloud storage, or third-party service connections that handle billing on an organization’s behalf.
Once card numbers are obtained, they are commonly tested in small transactions, sold in bulk on illicit markets, or combined with other personal details if those are also available. Organizations that learn of such exposure typically investigate, contain the access path if one is identified, and issue notices required by state law. That sequence is background context only; the Numotion filing does not attribute a cause, name a threat group, or describe containment steps, so those elements remain undisclosed for this incident.
United Seating and Mobility LLC dba Numotion and its sector
United Seating and Mobility LLC, known publicly as Numotion, operates in the complex rehabilitation technology and mobility equipment sector. Companies in this field supply and support wheelchairs, seating systems, and related assistive devices, often working with patients, caregivers, clinicians, and payers. That work routinely involves scheduling, ordering, billing, and insurance-related processes, which means such organizations typically handle names, contact information, clinical or functional details needed for equipment fitting, and payment or insurance data.
A breach affecting payment card numbers in this sector is consequential because customers may be individuals with ongoing medical or mobility needs who have shared financial information to obtain essential equipment. Even when the reported number of affected people is relatively small—here, 28—the exposure of card data can create immediate fraud risk and erode confidence in how sensitive billing information is protected. Sector context does not establish negligence in this case; it simply explains why payment data held by a mobility equipment provider carries practical weight for the people who rely on those services.
What was likely exposed
The notice lists credit or debit card numbers among the information exposed. That is the only data type named in the facts. Whether full card tracks, expiration dates, CVV codes, cardholder names, billing addresses, or other identifiers were also involved is not disclosed in the available summary and should not be assumed.
Organizations that sell or service mobility equipment commonly hold customer contact details, order and invoice records, insurance or benefits information, and payment method data. Those categories describe what such businesses typically maintain; they are not confirmed as part of this breach. Exact contents beyond the named credit or debit card numbers remain unconfirmed.
The real-world impact
For the 28 people identified in the notice, the primary concrete risk is unauthorized use of the exposed card numbers—fraudulent charges, card-not-present transactions, or attempts to add the numbers to digital wallets. Monitoring statements, requesting replacement cards, and watching for unfamiliar activity are ordinary responses. If only card numbers were involved and other identity documents were not, broader identity theft risk may be lower than in breaches that include Social Security numbers or full identity dossiers; that distinction depends on what else, if anything, was taken, which has not been detailed publicly here.
For the organization, consequences can include notification costs, potential regulatory follow-up under state breach laws, customer support burden, and reputational strain among patients and referral partners who expect careful handling of billing data. No public figure for financial loss or regulatory penalty is included in the facts. Impact on day-to-day operations or on clinical equipment delivery is likewise undisclosed.
Were you affected?
If you are a current or former Numotion customer in Massachusetts or elsewhere and you used a credit or debit card with the company, review the notice if you received one, check recent card statements for unfamiliar charges, and contact your card issuer promptly to discuss replacement or monitoring options. Keep records of any fraudulent activity and of communications with the company or your bank. Public detail does not list individual names, so receipt of an official notice remains the clearest signal that you were included in the affected group of 28.
As an additional check, you can run a free exposure scan of your email address to see whether that address has appeared in known breach datasets. That kind of scan does not replace the company’s notice or your bank’s fraud tools, but it can help you understand whether your email has surfaced in other incidents and whether you should tighten passwords and enable stronger account protections where you still use the same credentials.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
The Health Trust and its subsidiary, FASS Data Breach Notice (Massachusetts Attorney General)Ocean Edge Resort and Golf Club Data Breach Notice (Massachusetts Attorney General)Punch & Associates Investment Management, Inc. Data Breach Notice (Massachusetts Attorney General)Mortgage Trade Holding Co., LLC dba mTrade Data Breach Notice (Massachusetts Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.