
Sports technology provider Stack Sports is notifying users of a cybersecurity incident that may have exposed payment card information entered through its Sports Affinity web application platform.
According to a data breach notification sent to affected individuals, Stack Sports discovered suspicious activity on June 8, 2026, after its internal security monitoring systems detected unauthorized activity affecting the platform. The company said it immediately began containment efforts, launched an investigation with an independent incident response team, and engaged cybersecurity counsel to assist with the response.
The investigation determined that the unauthorized activity began around May 8, 2026, when an unknown actor placed malicious code on the Sports Affinity platform. The code was designed to capture payment-related information entered by users during the checkout process.
Stack Sports removed the malicious code from its servers on June 10, 2026. The company said residual elements of the code remained in a limited number of customer browser caches until those were forcibly cleared on June 22, 2026.
The incident was limited to users who accessed the Sports Affinity checkout process during the affected period. Stack Sports said the attack did not impact other Sports Affinity users, Sports Connect Club, or any other Stack Sports platforms. The company also stated that no payment information stored on the Sports Affinity platform was accessed because the platform does not store payment card data beyond encrypted transaction tokens.
The exposed information may have included cardholder names, payment card numbers, expiration dates, and CVV security codes. For users who paid through eCheck or ACH, checking account numbers may also have been affected. Stack Sports said the incident did not involve account credentials, profile information, uploaded documents, Social Security numbers, or driver's license numbers.
Following the discovery, the company implemented additional security measures and monitoring procedures designed to prevent similar incidents. It also completed a review of affected transactions and identified impacted individuals and mailing addresses on July 17, 2026.
Stack Sports is offering affected users 24 months of identity theft protection services through IDX, including credit and CyberScan monitoring, a $1 million insurance reimbursement policy, and managed identity theft recovery services. The company encouraged affected individuals to monitor payment card statements for unauthorized activity and contact their card issuer if suspicious transactions are detected.
Stack Sports said it does not believe the incident qualifies as a reportable breach under certain applicable laws but is providing notification to affected users as a precaution.







Leave a Reply