United Seating and Mobility LLC dba Numotion Data Breach Notice (Vermont Attorney General)
If you received a notice from United Seating and Mobility LLC dba, here’s what the filing says was exposed, and what to do about it.
United Seating and Mobility LLC dba Numotion notified Vermont residents of a data breach in a filing reported to the Vermont Attorney General on May 15, 2026, and the notice lists financial account codes, credit and debit account info among the information exposed.
The filing from United Seating and Mobility LLC, doing business as Numotion, states that the financial account codes and credit and debit account information of five Vermont residents were exposed. Because these details remain directly usable for fraud and do not expire, the breach creates an ongoing risk of unauthorized transactions even months or years from now.
Credit and debit account information does not lose its value
Unlike passwords, which can be changed, or temporary cards that can be replaced, the exposed credit and debit account information stays valid. Financial account codes tied to those accounts function the same way. Anyone who obtains this combination can attempt purchases, open new lines of credit in some cases, or initiate transfers before detection occurs. The record does not indicate that the data was encrypted or tokenized in a way that would have prevented misuse.
Numotion has a legal duty to notify the affected individuals directly, usually by mail. If you have not received a letter, it is likely your information was not part of the five-person group. However, because the filing does not state when the incident occurred, anyone who has moved since then should contact Numotion directly to confirm whether their records were included.
What this exposure actually enables
With credit and debit account details, attackers do not need passwords or login credentials. They can test the numbers on retail sites, subscription services, or payment processors that do not require additional verification. Small, repeated charges often go unnoticed until the monthly statement arrives. Financial account codes can also help link this data to other records an attacker may already hold, increasing the precision of future fraud attempts.
No permanent government or biographic identifiers such as Social Security numbers were listed in the filing. No passwords were exposed. This limits some identity-theft scenarios but does nothing to reduce the immediate fraud risk created by the usable payment information.
The limited scale does not reduce your risk
Only five people are named in this Vermont filing. That small number does not make the exposed data less dangerous for those affected. Each record contains payment details that retain their full value to a fraudster. The fact that the breach was narrow simply means the organization must still treat every one of those five records as a serious, long-term liability.
Why the absence of certain data matters
The filing lists only financial account codes and credit and debit account information. It does not include passwords, Social Security numbers, driver’s license numbers, or medical details. This is genuine good news on those fronts. You do not face the permanent exposure that comes with an SSN or the account takeover risk that follows a password breach. The threat here is strictly financial fraud, not full identity theft or credential-based login attacks.
How long the information stays dangerous
Credit and debit account data can be used as long as the underlying accounts remain open. Even after cards are canceled and replaced, related account codes sometimes retain utility. Monitoring must therefore continue for years, not weeks. Early detection is the only practical defense once the data has left Numotion’s control.
Concrete steps that address this exact exposure
- Review every credit and debit card statement the moment it arrives. Look for small or unfamiliar charges. Set up transaction alerts for any amount over $1 so you catch attempts immediately.
- Contact the banks or card issuers tied to any accounts that may have been included. Ask them to flag the accounts for fraud, issue new card numbers, and add extra verification requirements on transactions.
- Place a fraud alert with the three major credit bureaus. This forces lenders to verify your identity before opening new accounts in your name and gives you an early warning if someone tries.
- Enroll in free credit monitoring offered by Numotion or provided through your bank. Even basic monitoring can surface new account applications or address changes you did not authorize.
- If you receive the notification letter, follow its specific instructions exactly. The organization is required to provide guidance tailored to the exact data that was exposed for your record.
The record does not disclose how the breach occurred, whether the data was copied or simply viewed, or what security measures were in place. Those details remain unknown. What is known is narrow but serious: five people had their usable financial payment information exposed, and that information does not expire. The letter you may receive is the only reliable way to know for certain if you are one of them. Until it arrives, treat any linked accounts with heightened vigilance.
What to do now
Steps that match what this notice says was exposed
Every step below is free and you do it yourself, and none of it depends on United Seating and Mobility LLC dba.
- Tell your bank before you do anything else. Account and routing details are the fastest-moving of the fields in this notice. Call the number on the back of your card rather than any number in an email, and ask them to watch the account and reissue the card.
One more, whatever was exposed: a breach notice is a favourite disguise for a phishing email. If a message about this arrives, do not use its links — go to the company’s site yourself, or call the number on your statement.