SPay Inc
ent_8f498f8bbf2b6aa2c3a0f095
Disclosures
2
State AG · 2 jurisdictions
Incidents
1
filings grouped by incident
Max affected reported
—
no filed count in sample
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- SPay Inc
- Normalized
- spay— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- No match
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (2)newest first
- 🐻California State AGas victim2026-07-27
SPay Inc dba Stack Sports experienced a cybersecurity incident where unauthorized code was placed on its Sports Affinity web application platform. The malicious code captured payment card information (cardholder name, card number, expiration date, CVV, and checking account numbers) entered during the checkout process. The incident window began on May 8, 2026, and was discovered on June 8, 2026. The malicious code was removed by June 10, 2026. The company engaged forensic investigators and implemented additional security measures. Affected individuals were offered 24 months of identity theft protection.
- 🏛️Massachusetts State AGas victim2026-07-01
SPay Inc (dba Stack Sports) notified Massachusetts residents of a cybersecurity incident involving its Sports Affinity web application. Unauthorized code was placed on the platform between May 8 and June 10, 2026, capturing payment card details (numbers, CVV, expiration) and checking account numbers during checkout. The incident was discovered on June 8, 2026, and notices were sent on July 27, 2026. Stack Sports engaged forensic investigators, removed the malicious code, and offered 24 months of identity theft protection.