Were you recently affected by a data breach?

Swish Sports Data Breach

Swish Sports, operator of the Swish pick-up sports app, notified users of a data event involving personal information following a review of its website security.

Swish Sports
Date of Breach: Not publicly disclosed; notice letter dated September 16, 2026
CAU logo

Who was affected:

Clients of Swish Sports

Impacted Data:

Not publicly disclosed beyond confirmation that personal information was involved

Swish Sports, LLC, a Provo, Utah-based company that operates the Swish mobile app for organizing pick-up sports games and pickleball leagues, has notified individuals of a data event involving their personal information. The company sent written notice explaining that it moved quickly to investigate the incident and assess the security of its website after learning of it.

Companies that collect personal information from app users and league participants have a responsibility to keep that data secure, and when an incident occurs, affected individuals deserve a clear explanation of what happened and what they can do to protect themselves.

Swish Sports’s Data Breach Investigation

According to the notice sent to affected individuals, Swish Sports learned of a data event involving personal information and, upon learning of it, moved to investigate, respond, and assess the security of its website. The company states that, as part of its ongoing commitment to information security, it is reviewing its existing policies and procedures following the incident.

The notice states that, due to requirements imposed by Massachusetts law, Swish Sports is not providing further detail about the nature of the event in the letter itself. The company has not publicly disclosed the specific cause of the incident, the exact dates it occurred or was discovered, or a complete list of the data types involved beyond what is included in the notification.

Swish Sports operates both a consumer mobile app for organizing pick-up games and a separate platform used by pickleball and racquet clubs to manage leagues, tournaments, and court bookings, meaning the company’s systems handle personal information from both individual app users and league participants registered through partner organizations. A website-related security event at a company like this can potentially affect account information collected through either side of the business.

Technology companies that operate consumer-facing apps and websites are common targets for attackers seeking account credentials, contact information, or payment-related data, since a single vulnerability in a website or app backend can expose records tied to a large number of users at once. The specific wording in Swish Sports’s notice, that the company assessed the security of its website, suggests the incident was related to the company’s web infrastructure rather than a physical loss of records.

Individuals who use apps to organize recreational sports, book courts, or register for leagues often do not think of that information as high-risk, but a user profile combined with contact information and any stored payment details can still be valuable to a cybercriminal for follow-up phishing or unauthorized account access. Anyone who received this notice should review their Swish account for any unfamiliar activity and update their account password as a precaution, regardless of the exact data types confirmed in the notice.

When Did This Breach Occur?

Swish Sports’s notice does not specify the exact dates the data event occurred or was discovered. The notice letter provided to affected individuals is dated September 16, 2026.

What Information Was Breached?

Swish Sports has not publicly disclosed a complete list of the specific data types involved in this incident beyond confirming that personal information was affected.

What You Can Do

If you received a notice from Swish Sports about this incident, consider taking the following steps:

  • Change your Swish app account password and enable any available additional login security.
  • Review your Swish account for any unfamiliar activity, bookings, or payment methods.
  • Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion if you provided any financial information through the app.
  • Monitor your financial accounts closely for unfamiliar activity in the coming months.
  • Contact Swish Sports directly using the call center number provided in your notice letter if you have questions about your account.

File a Data Breach Lawsuit Against Swish Sports

If you received a notice that your personal information was exposed in this incident, you may have legal options available to you. Companies that collect personal information through consumer apps and websites are expected to take reasonable steps to protect it, and when that trust is broken, affected individuals may be entitled to pursue compensation.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Between March 28, 2026, and April 12, 2026 (at vendor Ernst & Young LLP)
Date of Breach: On or about August 26, 2026
Date of Breach: On or about March 6, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.