What Sports Affinity Users Need to Know
On June 8, 2026, SPay, Inc., doing business as Stack Sports (“Stack Sports”), identified suspicious activity on its Sports Affinity web application platform through internal security monitoring. According to the company’s notice, unauthorized code had been placed on the platform that captured certain payment card information entered by consumers during the checkout process. Stack Sports says the unauthorized activity began on or about May 8, 2026; the malicious code was removed from its servers by June 10, 2026, though residual capture code reportedly remained in some customers’ browser caches until it was forcibly cleared on June 22, 2026.
Stack Sports finished verifying which transactions and individuals were affected on July 17, 2026, and began mailing notice letters on July 27, 2026. The company describes the incident as limited to users who accessed the Sports Affinity checkout process during the incident window, and states it did not affect Sports Connect Club or other Stack Sports platforms. Stack Sports also states that it does not believe the incident “rises to the level of a breach under certain applicable laws,” though it is notifying affected individuals and offering identity protection services regardless.
Why the Timeline Matters
Stack Sports says the unauthorized card-skimming activity began around May 8, 2026, and wasn’t detected until June 8, 2026, about a month later. The company then took until July 27, 2026 to begin notifying affected individuals, roughly two and a half months after the activity began and about seven weeks after it was first identified. Stack Sports has not explained why verifying affected transactions took from June 8 to July 17, 2026.
What Information Was Exposed?
Based on the official notice, the information potentially affected may include:
- Cardholder name
- Payment card number
- Card expiration date
- Card security code (CVV)
- Checking account number (for individuals who paid by eCheck or ACH)
Stack Sports states the incident did not involve Social Security numbers, driver’s license numbers, Stack Sports account login credentials, or any documents stored within a user’s account.
What Is Stack Sports Offering Affected Individuals?
Stack Sports is offering 24 months of complimentary credit and CyberScan monitoring through IDX, including a $1,000,000 insurance reimbursement policy and fully managed identity theft recovery services. Individuals who received a letter can enroll using their Enrollment Code before the October 27, 2026 deadline, or call 1-855-830-6490 with questions.
Your Information Is at Risk
Because the exposed data is payment card information, card numbers, expiration dates, and CVV codes, and in some cases checking account numbers, affected individuals face a real risk of fraudulent charges. Unlike a stolen Social Security number, compromised card data can often be addressed by canceling and reissuing the affected card, but individuals should still act quickly to limit any damage.
Affected individuals should:
- Enroll in the free IDX credit and CyberScan monitoring before October 27, 2026
- Review card and bank statements closely for unauthorized or unfamiliar charges
- Contact their card issuer immediately to report suspicious activity or request a replacement card
- Consider a fraud alert or credit freeze with Equifax, Experian, and TransUnion
- Consider speaking with a data breach attorney about legal options
Do You Have Legal Options?
Companies that process online payments have a legal obligation to secure that data using reasonable safeguards. A card-skimming incident that went undetected for roughly a month and took several more weeks after detection to fully investigate and notify affected individuals raises real questions about whether Stack Sports met that obligation. Affected individuals may have legal rights and remedies worth discussing with an attorney.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Residents of California may be entitled to additional protections under the California Consumer Privacy Act (CCPA), which provides enhanced rights regarding the collection, use, and safeguarding of personal information.
FAQ
How many people were affected by the Stack Sports data breach?
Not publicly disclosed. California does not require the state to publish a population figure, and no other source has confirmed one yet.
What information was exposed in the breach?
Cardholder name, payment card number, expiration date, CVV, and, for those who paid by eCheck or ACH, checking account number. Stack Sports states no Social Security numbers or driver’s license numbers were involved.
Why did it take so long for Stack Sports to notify people?
The unauthorized activity began around May 8, 2026 and was detected June 8, 2026, but notice letters weren’t mailed until July 27, 2026 — about two and a half months after the activity began.
Has anyone sued Stack Sports over this breach?
Not confirmed as of this writing.
What should I do if I received a notification letter?
Enroll in the free IDX monitoring before the deadline, watch your card and bank statements closely, contact your card issuer about any suspicious charges, and consider speaking with a data breach attorney.