What Happened in the Stack Sports Data Breach?
Stack Sports, the company behind SPay, Inc., has confirmed a data security incident tied to its Sports Affinity checkout system. The company reported that hidden code appeared on the payment page without authorization. As a result, the code may have quietly copied payment details as customers typed them in during checkout.
According to the company’s own account, this unauthorized code became active around May 2026. Internal security monitoring flagged suspicious activity roughly a month later, in June 2026. That gap is common in this type of intrusion, since skimming code intercepts data in real time rather than pulling it from a stored file, making it harder to catch right away.
Once the activity was flagged, Stack Sports brought in outside forensic investigators and legal counsel to look deeper into the incident. That investigation confirmed the malicious code had been designed specifically to grab checkout information. The company says it removed the code from its servers within days, though some leftover elements lingered in certain customer browser caches for a few more weeks before being cleared.
Stack Sports then spent additional weeks reviewing transaction records to figure out exactly whose payment information may have been touched. That review wrapped up in mid-July 2026, and written notices to affected customers went out shortly afterward. The company has stated the incident was contained to the Sports Affinity platform and did not reach its other software products.
Who was affected?
Anyone who entered payment information through the Sports Affinity checkout page during the exposure window could be affected. This likely includes parents, coaches, and administrators connected to youth and amateur sports organizations that rely on Stack Sports for registration and payment processing.
Stack Sports has not publicly released a specific number of affected individuals. Because the platform serves sports organizations nationwide, the population involved could span many states and include both one-time and recurring payers. The company has said its other platforms, including Sports Connect Club, were not part of this incident.
It also remains unclear whether any minors’ payment information was entered by parents on their behalf during checkout, though this is common on youth sports registration platforms. Anyone who made a payment on the affected system during the relevant months should assume they could be included until they receive or confirm otherwise.
What Information Was Potentially Exposed?
The exposed data centers on payment details entered directly into the checkout page rather than information stored in a database. Because of how the malicious code worked, it could capture data the moment a customer typed it in.
- Cardholder names
- Payment card numbers
- Card expiration dates
- Card security codes (CVV)
- Checking account numbers for customers who paid by eCheck or ACH
Stack Sports has stated that Social Security numbers, driver’s license numbers, account credentials, and stored documents were not part of this incident. Even so, the categories that were exposed are sensitive enough to cause real financial harm.
Card numbers paired with expiration dates and CVVs give criminals nearly everything needed to make fraudulent online purchases immediately. Because CVVs were included, this is more serious than many breaches, since retailers often require that code to complete a transaction. In addition, checking account numbers submitted through ACH or eCheck payments could potentially be used to attempt unauthorized withdrawals, which makes monitoring bank activity just as important as watching card statements.
What is the company doing?
Once Stack Sports discovered the suspicious code, it moved to remove it from its servers within a couple of days. The company also worked to clear residual elements that remained in some customer browser caches for a longer stretch afterward. Alongside this, it brought in independent forensic experts and cybersecurity counsel to investigate the full scope of the intrusion.
After finishing its review of affected transactions, Stack Sports began sending written notification letters to impacted customers. The company also filed notice with the California Attorney General’s Office, as required under state breach notification law. As part of its response, Stack Sports is offering identity theft protection services through IDX to individuals affected by the incident.
Monitor Your Financial Accounts Closely
Review your card and bank statements carefully for any charges you do not recognize, even small ones. Fraudsters often test stolen card numbers with tiny transactions before attempting larger purchases.
If you spot anything suspicious, contact your card issuer or bank right away to dispute the charge and request a replacement card. Acting quickly can limit your financial exposure and stop further unauthorized use.
Consider a Fraud Alert or Credit Freeze
Because card and bank account numbers were involved, placing a fraud alert with one of the three major credit bureaus is a reasonable precaution. This makes it harder for someone to open new credit in your name using stolen information.
A credit freeze offers even stronger protection by restricting access to your credit file entirely. You can lift it temporarily whenever you need to apply for new credit yourself, so it does not have to be permanent.
Enroll in the Offered Identity Protection Service
Stack Sports is providing identity theft protection through IDX at no cost to affected individuals. Enrolling gives you an added layer of monitoring beyond what you can easily do on your own.
Because this service was made available specifically in response to this breach, taking advantage of it makes sense even if you have not noticed any suspicious activity yet. Early enrollment means faster alerts if your information does surface elsewhere.
Watch for Phishing Attempts Referencing This Breach
Scammers sometimes use news of a breach to send fake emails or texts pretending to be from the affected company. These messages often ask you to confirm account details or click a suspicious link.
Be cautious of any unsolicited message referencing Stack Sports or this incident. Legitimate companies will not ask you to provide sensitive information through an unexpected email or phone call, so verify independently before responding.
Report Suspected Fraud or Identity Theft
If you notice unauthorized charges or believe your identity has been misused, report it to the Federal Trade Commission at IdentityTheft.gov. This creates an official record and can help you recover from fraud more efficiently.
You should also consider speaking with a data breach attorney to understand your options. A free case evaluation can clarify whether you qualify to join a claim seeking compensation for the exposure of your financial information.
More Information
Official data breach notification from California Attorney General
