Malicious code embedded in SpinLife's checkout page skimmed payment information from customers who attempted purchases on spinlife.com between February 1 and March 3, 2026, exposing names alongside card details. SpinLife, owned by Numotion, says there's no confirmed fraud yet but is offering free credit monitoring. Affected customers should immediately contact their card issuer to monitor statements and consider requesting a new card.
| Company | SpinLife |
|---|---|
| Industry | Healthcare |
| Data Types Exposed | Name, Payment Card Details, Financial Account Codes, Credit/Debit Account Information |
| People Affected | Not Publicly Disclosed |
| Attack Method | Web Skimmer |
| Regulators Notified | Vermont Attorney General |
Were you affected by this breach?
You may be owed compensation.
Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.
Check if you qualify — free reviewWhat Happened in the SpinLife (Numotion) Data Breach?
SpinLife, an online retailer of wheelchairs, scooters, and other mobility equipment, recently notified customers that unauthorized code was present on its website’s checkout process. SpinLife is owned by United Seating and Mobility LLC, which does business as Numotion — so this incident is filed with state regulators under the Numotion corporate name, even though the notification letters were issued directly by SpinLife.
According to the notification letter, the unauthorized code was active during checkout on spinlife.com for customers attempting to make purchases between February 1, 2026 and March 3, 2026. The code was potentially capable of capturing customer payment details entered at checkout — a type of attack commonly known as a web skimmer. SpinLife reviewed its transaction data to determine which specific customers may have been affected.
SpinLife has stated it is not aware of any fraud or identity theft connected to this incident. However, out of caution, the company is offering free credit monitoring and identity protection services to those affected.
Who Was Affected?
Individuals who attempted to make a purchase on SpinLife’s website between February 1, 2026 and March 3, 2026 may have had their payment information exposed. Vermont’s filing lists just 5 affected residents in that state, but because SpinLife sells nationally, the full number of affected customers across all states has not been publicly disclosed.
What Information Was Potentially Exposed?
Per the notification letter, this incident potentially involved your name in combination with payment card details entered during checkout. State regulators have categorized this as financial account codes and credit/debit account information.
- Name
- Payment card details (financial account codes, credit/debit account information)
This type of data is especially attractive to criminals because it can be used directly to attempt fraudulent purchases. Unlike a stolen password, card details connect straight to real money, so anyone affected faces a tangible risk of financial fraud.
What Is SpinLife Doing?
SpinLife engaged third-party specialists to investigate the incident and has taken steps to further secure its checkout process to reduce the chance of a similar incident happening again.
The company is offering complimentary credit monitoring and identity protection services through CyberScout to affected individuals. If you received a notification letter, it includes a unique enrollment code — enrollment must be completed within 90 days of the letter’s date.
Questions can be directed to SpinLife at CustomerService@SpinLife.com, or by mail to Attn: Privacy Officer, 330 W Spring St, Ste 303, Columbus, OH 43215.
What Should Affected Individuals Do?
Enroll in the Free Credit Monitoring
If you received a letter from SpinLife, it includes a unique code to enroll in complimentary credit monitoring and identity protection at no cost. This must be done within 90 days of the letter date, so don’t wait to sign up.
Review Your Card Statements Closely
Because payment card details were involved, check your card and bank statements frequently for small, unfamiliar charges — fraudsters often test stolen card numbers with minor purchases before attempting larger ones. If you spot anything suspicious, contact your card issuer immediately to dispute the charge and request a replacement card.
Consider a Fraud Alert or Credit Freeze
Placing a fraud alert or credit freeze is a strong protective step whenever payment information is exposed. A fraud alert requires lenders to verify your identity before opening new credit in your name, while a credit freeze blocks new credit inquiries entirely. Contact any of the three major credit bureaus to set either one up.
Watch for Phishing Attempts
After a breach like this, scammers often use exposed information to craft convincing phishing emails or calls, sometimes pretending to be SpinLife, Numotion, or your bank. Never click links or share personal information in response to an unsolicited message — instead, contact the company directly using a verified phone number or website.
Consult a Data Breach Attorney
If you received notice that your information was exposed in this breach, it may be worth speaking with a data breach attorney to understand whether you qualify for compensation. Many attorneys offer free case evaluations for individuals affected by payment data breaches, so reaching out costs you nothing upfront.
Get a Free Case Review
Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.
More Information
View the public data breach notification listing from Oregon Department of Justice
View the public data breach notification listing from Vermont Attorney General
