What Happened
In March 2026, Segway-Ninebot (segway.com) suffered a major server-side data breach when an alleged database containing millions of customer records from over 160 countries was exfiltrated and put up for sale on dark web marketplaces following the March 4 takedown of the LeakBase forum. The exposed data included extensive personally identifiable information (PII) such as full names, verified email addresses, and mobile phone numbers; micro-mobility metadata like internal device identifiers, ride history logs, and potentially precise GPS coordinates; and authentication details including usernames and hashed passwords, enabling risks like credential stuffing, smart-vehicle phishing, doxxing, and stalking. This incident differs from Segway’s prior 2022 Magecart attack, which involved payment card skimming on its Magento-based online store starting January 6, 2022. No official confirmation or exact record count was provided by Segway, and the breach’s full scope remains unverified beyond cybersecurity alerts.
