SPay Inc
bd_443fdcd624ea3269 · schema v1 · pii pii-v1
Full breach record for SPay Inc →SPay Inc (dba Stack Sports) notified Massachusetts residents of a cybersecurity incident involving its Sports Affinity web application. Unauthorized code was placed on the platform between May 8 and June 10, 2026, capturing payment card details (numbers, CVV, expiration) and checking account numbers during checkout. The incident was discovered on June 8, 2026, and notices were sent on July 27, 2026. Stack Sports engaged forensic investigators, removed the malicious code, and offered 24 months of identity theft protection.
J jump to incidentP pin to compareR raw source
Incident timeline
May 8, 2026
Begins
Jun 8, 2026
Discovered
Jul 27, 2026
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- California State AGbd_65e50669f15072252026-07-27Candidate
- Nebraska State AGbd_baa30e309092f2a52026-07-27Verified
- Washington State AGbd_e5b0ba8053af98522026-07-27Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.