Were you recently affected by a data breach?

Stack Sports Data Breach

Stack Sports (SPay, Inc.), a Plano, Texas sports-management software company, found unauthorized code on its Sports Affinity payment checkout platform that may have captured customers’ payment card details. Notices went out July 27, 2026. Affected customers should review card statements closely and enroll in the identity protection offered.

Stack Sports
Date of Breach: Unauthorized activity began around May 8, 2026 and was discovered by Stack Sports on June 8, 2026; affected individuals began receiving notice on July 27, 2026.
CAU logo

Who was affected:

Clients of Stack Sports

Impacted Data:

Cardholder names, payment card numbers, card expiration dates, card security codes (CVV), and checking account numbers for customers who paid by eCheck or ACH

Stack Sports, operated by SPay, Inc., is a widely used sports management software company based in Plano, Texas, serving youth and amateur sports organizations across the country. The company recently notified customers that unauthorized code was discovered on its Sports Affinity payment checkout platform, potentially exposing payment card information entered during the checkout process.

Companies that process online payments have a responsibility to safeguard the financial information their customers enter, and a breach like this one can leave affected individuals vulnerable to fraudulent charges and further exploitation of their payment data.

Stack Sports’s Data Breach Investigation

According to a notification letter filed with the California Attorney General’s Office, Stack Sports identified suspicious activity affecting its Sports Affinity Platform through internal security monitoring on June 8, 2026. The company engaged an independent forensic incident response team and cybersecurity counsel to investigate. That investigation determined that unauthorized code had been placed on the Platform, beginning on or about May 8, 2026, which was designed to capture certain payment-related information entered by consumers during the checkout process. Stack Sports states the malicious code was fully removed from its servers by June 10, 2026, though residual elements remained in an isolated number of customer browser caches until they were forcibly cleared on June 22, 2026. A review of impacted transactions to identify affected individuals was finalized on July 17, 2026, and notification letters began going out on July 27, 2026.

Payment-skimming attacks like the one described in this notice, sometimes called web-skimming or e-commerce card-skimming attacks, have become an increasingly common method for cybercriminals to harvest financial data directly from the checkout pages of legitimate businesses, often without the business’s customers ever knowing their information was compromised in real time. Because the malicious code intercepts data as it is entered rather than stealing it from a stored database, these attacks can be difficult to detect until unusual account activity or an internal security review surfaces them, which may explain the roughly one-month gap between when the incident is reported to have begun and when it was ultimately discovered.

Stack Sports states that the incident was limited specifically to users of the Sports Affinity Platform who accessed its checkout process during the incident window, and that it did not affect the company’s other platforms, including Sports Connect Club, nor any account credentials, stored documents, or account profile information. The company also states it does not believe Social Security numbers or driver’s license numbers were involved. Even so, exposed payment card numbers, expiration dates, and security codes can be used to make fraudulent charges quickly once compromised, and checking account numbers submitted through ACH or eCheck payments are similarly sensitive since they can potentially be used for unauthorized electronic withdrawals.

Data breach notification laws, including California’s, generally require companies to notify affected residents once they determine that personal information has been compromised, though the exact requirements and reporting thresholds vary from state to state. The gap between an incident’s start date and its public disclosure is common across many breach notifications, since a thorough forensic investigation to confirm scope and affected individuals takes real time to complete properly. That said, the length of exposure in an active payment-skimming scenario matters, because every transaction processed on a compromised checkout page during that window is a potential point of exposure for the customer involved.

Anyone who made a payment through the Stack Sports Sports Affinity Platform during the relevant window should treat this notice seriously, even if Stack Sports has stated it has no evidence yet of actual fraudulent use of the exposed information. Financial account exposure of this kind is often followed by attempted fraudulent charges or, in some cases, by phishing attempts that reference the breach to try to extract even more information from affected consumers.

When Did This Breach Occur?

Stack Sports states the unauthorized activity on its Sports Affinity Platform began on or about May 8, 2026, and was discovered on June 8, 2026. The malicious code was removed from its servers by June 10, 2026, with residual browser-cache elements cleared by June 22, 2026. The company finalized its review of affected transactions on July 17, 2026, and began sending notification letters to affected individuals on July 27, 2026.

What Information Was Breached?

According to Stack Sports’s notification, the information potentially exposed includes cardholder names, payment card numbers, card expiration dates, card security codes (CVV), and, for individuals who paid by eCheck or ACH, checking account numbers. The company states that account credentials, stored account documents, and Social Security or driver’s license numbers were not involved in this specific incident.

What You Can Do

If you made a payment through the Stack Sports Sports Affinity Platform and believe you may have been affected, consider taking the following steps:

  • Closely review your payment card and bank statements for any unauthorized or unfamiliar charges.
  • Contact your card issuer or bank immediately if you spot suspicious activity.
  • Enroll in the identity theft protection services Stack Sports is offering through IDX.
  • Consider placing a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, and TransUnion).
  • Be cautious of unsolicited calls, texts, or emails referencing this breach, which may be phishing attempts.
  • Report any suspected identity theft or fraud to the Federal Trade Commission at IdentityTheft.gov.

File a Data Breach Lawsuit Against Stack Sports

If your payment information was exposed in the Stack Sports data breach, you may have legal options available to you. Companies that process online payments can potentially be held accountable when inadequate security measures allow customer financial data to be compromised.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: May-June 2026 (irregularities detected ~May 26, 2026; ransomware group claim ~June 4, 2026)
Date of Breach: May 27, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.