SPay Inc
bd_baa30e309092f2a5 · schema v1 · pii pii-v1
Full breach record for SPay Inc →SPay Inc (dba Stack Sports) disclosed a cybersecurity incident affecting its Sports Affinity web application platform. Unauthorized code was placed on the platform between May 8 and June 10, 2026, capturing payment card information (card numbers, CVVs, checking account numbers) entered during checkout. The incident was discovered on June 8, 2026, and notices were sent on July 27, 2026. Stack Sports engaged forensic investigators, removed the malicious code, and offered 24 months of identity theft protection services to affected users.
J jump to incidentP pin to compareR raw source
Incident timeline
May 8, 2026
Begins
Jun 8, 2026
Discovered
Jul 27, 2026
Filed
Linked disclosures
Why this link?Regulatory filings (3) · sorted by filing gap
- Massachusetts State AGbd_443fdcd624ea32692026-07-27Verified
- California State AGbd_65e50669f15072252026-07-27Candidate
- Washington State AGbd_e5b0ba8053af98522026-07-27Verified
Filing propagation · 4 filings · 4 states
View merged incident ↗Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.