United Seating and Mobility LLC dba Numotion Data Breach Notice (Vermont Attorney General): What Was Exposed & What To Do
United Seating and Mobility LLC, doing business as Numotion, disclosed a data breach on May 15, 2026, that exposed financial account codes and credit- and debit-card information belonging to five individuals. Anyone who received services from the company should review their accounts and financial statements for signs of unauthorized activity.
United Seating and Mobility LLC, doing business as Numotion, notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on May 15, 2026. Public records from that notice state that five people were affected and that the information involved included financial account codes along with credit and debit account information.
The disclosure is limited. Timing of the underlying incident, how systems were accessed, and broader operational details have not been set out in the available notice. Even with a small reported number of individuals, exposure of payment-related data carries concrete follow-on risks that warrant clear explanation for anyone who may be among those notified.
What happened
According to the Vermont Attorney General filing dated May 15, 2026, United Seating and Mobility LLC dba Numotion provided notice of a data breach affecting five people. The notice lists financial account codes and credit and debit account information among the categories of data exposed.
Public detail stops there. The filing does not describe when the incident began or was discovered, whether it involved unauthorized access to a network, a vendor system, lost media, or another vector, or whether any other categories of personal information were involved. No threat actor is named in the disclosed material, and no technical indicators or ransom-related claims appear in the facts available from the regulator notice. What is established is the organization’s report to the Vermont Attorney General, the headcount of five affected individuals, and the named financial data types.
How a breach like this happens
Incidents that surface as notices involving financial account codes and payment-card details typically follow a small set of patterns, though none of those patterns is confirmed for this specific case. Common pathways include compromise of systems that store billing or claims data, phishing or credential theft that leads to access to customer or patient finance records, misconfigured cloud storage or backups, or intrusion into a third-party service that processes payments or reimbursements on an organization’s behalf.
Once an attacker or unauthorized party obtains account numbers, routing or account codes, and related identifiers, the material can be used for fraudulent charges, account takeover attempts, or sale on criminal markets. Defenders usually learn of such events through monitoring alerts, customer reports of suspicious activity, law-enforcement tips, or internal audits. Organizations then assess scope, contain access, and determine notification obligations under state law. Because the Numotion notice does not describe method or timeline, the above remains general background on how similar financial-data incidents often unfold, not a reconstruction of this event.
About United Seating and Mobility LLC dba Numotion
United Seating and Mobility LLC operates as Numotion and works in the complex rehabilitation technology sector. Companies of this kind supply and support mobility equipment such as custom wheelchairs and related seating systems, often coordinating with clinicians, insurers, and patients who need durable medical equipment. That work routinely involves collecting and retaining information needed for ordering, fitting, billing, insurance claims, and ongoing service.
Organizations in this space commonly hold names, contact details, insurance identifiers, clinical or functional assessment notes tied to equipment needs, and payment or reimbursement data. A breach affecting even a small number of records can therefore touch sensitive financial channels tied to medical equipment purchases or insurance processes. The Vermont notice does not expand on Numotion’s internal systems or the precise business process that held the exposed data; the consequential point is simply that a mobility and seating provider handling payment-related information has reported limited exposure of financial account codes and credit and debit account details.
What was likely exposed
The Vermont Attorney General notice names the exposed categories as financial account codes and credit and debit account information. Those labels indicate payment-related identifiers—such as account or routing-style codes and card account details—rather than a full inventory of every field that may have been present in the same systems.
Exact record contents beyond those named types are unconfirmed. Organizations that bill for medical equipment and coordinate insurance commonly also maintain names, addresses, dates of birth, insurance member numbers, and order or claim references. None of those additional categories is stated as exposed in the facts provided here, so they must not be treated as confirmed for this incident. What is known is limited to the five affected individuals and the financial account codes plus credit and debit account information listed in the notice.
Why it matters
Financial account codes and credit or debit account data can enable unauthorized transactions, attempts to open or take over accounts, and social-engineering attacks that reference real payment details to appear legitimate. For people who rely on specialized mobility equipment, billing and insurance interactions may already be complex; misuse of payment data adds a separate layer of financial risk and time spent monitoring statements and disputing charges.
For the organization, a reported breach triggers notification duties, potential regulatory follow-up, and the operational cost of investigation and customer support. The small reported figure of five people does not eliminate individual harm; it does mean the public footprint of the event is narrower than large-scale healthcare breaches. Still, anyone who receives a notice should treat the named data types as genuinely sensitive and act accordingly. No finding of negligence or specific security failure is stated in the available disclosure, and none should be assumed from the mere fact of notification.
What to do if you're exposed
If you receive a notice from Numotion or believe you may be one of the five individuals referenced, start with the steps the letter itself recommends and keep a copy for your records. Monitor bank and card statements closely for unfamiliar charges; contact the financial institution promptly to report fraud, request a new card or account number if appropriate, and ask about alerts. Consider a fraud alert with the major credit bureaus and review your credit reports for unexpected accounts. Change passwords on any related online billing or patient portals and enable multi-factor authentication where available. Be cautious of unsolicited calls or messages that reference the breach and ask for further personal or payment details.
You can also run a free exposure scan of your email address to check whether that address has already appeared in other known breach datasets, which can help you prioritize password changes and monitoring. If you later see confirmed misuse, document it and report it to your bank and, if needed, to law enforcement or the Federal Trade Commission through their identity-theft resources. Public detail on this incident remains limited to the May 15, 2026 Vermont filing, the count of five people, and the named financial data types; treat unconfirmed claims from unofficial sources with skepticism and rely on official notices for personal next steps.
AICompiled with AI assistance from public sources and published under our editorial standards.
How this breach connects
More recent breaches
Secure Healthcare Information Management, LLC Data Breach Notice (Vermont Attorney General)The Hudson River Museum of Westchester, Inc. Data Breach Notice (Vermont Attorney General)Family Medical Associates of Raleigh, PA Data Breach Notice (Vermont Attorney General)Financial Administrative Support Services Data Breach Notice (Vermont Attorney General)Latest breaches
Verified breach
Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.
Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.