SPay Inc
bd_65e50669f1507225 · schema v1 · pii pii-v1
Full breach record for SPay Inc →SPay Inc dba Stack Sports experienced a cybersecurity incident where unauthorized code was placed on its Sports Affinity web application platform. The malicious code captured payment card information (cardholder name, card number, expiration date, CVV, and checking account numbers) entered during the checkout process. The incident window began on May 8, 2026, and was discovered on June 8, 2026. The malicious code was removed by June 10, 2026. The company engaged forensic investigators and implemented additional security measures. Affected individuals were offered 24 months of identity theft protection.
J jump to incidentP pin to compareR raw source
Incident timeline
May 8, 2026
Begins
Jun 8, 2026
Discovered
Jul 27, 2026
Filed
vs. sector median
1 wks faster
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_443fdcd624ea32692026-07-27Verified
- Nebraska State AGbd_baa30e309092f2a52026-07-27Verified
- Washington State AGbd_e5b0ba8053af98522026-07-27Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.