Skip to content

Stack Sports checkout skimmer exposed payment data

Summary

Stack Sports logo

Malicious code on Stack Sports’ Sports Affinity checkout pages captured payment information entered from about May 8 until residual elements were cleared June 22, 2026. Stack Sports notified affected users after finalizing its transaction review July 17; the exposed fields may have included cardholder names, card numbers, expiration dates, CVVs and some checking-account numbers.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted locations

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

  • Malware

    Malicious software other than ransomware used to compromise or disrupt systems.

Data impacts

  • Data exposure

    Data was made accessible to unauthorized parties through misconfiguration, system compromise, improper access controls, or another unintended condition.

  • Unauthorized data access

    An unauthorized party accessed or viewed data without evidence that the data was copied, removed, altered, or publicly disclosed.

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

Operational impacts

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

DysruptionHub assesses with high confidence that Stack Sports experienced a web-skimming incident on its Sports Affinity checkout process. In a July 27 consumer notice, Stack Sports said an unauthorized person placed code on the platform that captured payment-related information entered during checkout. The company dated the unauthorized activity to about May 8, detected it through internal monitoring June 8, removed the malicious code from its servers by June 10 and forcibly cleared residual elements from an isolated number of customer browser caches June 22.

The notice narrowed the affected environment to Sports Affinity users who accessed checkout during the incident window. Stack Sports said the incident did not affect other Sports Affinity users, Sports Connect Club or other Stack Sports platforms, and did not involve data stored on Sports Affinity beyond encrypted transaction tokens.

Operational significance

Utah Youth Soccer’s earlier June 24 update documented the incident’s operational effect: the association disabled registration and payments after families reported unauthorized card charges, then restored those functions after Stack Sports said the source had been neutralized. FOX 13 reported that families could not register and that multiple parents replaced cards after suspicious charges.

The later notice shows the data impact extended beyond the initially documented Utah customer. The California Department of Justice’s breach record identifies a May 8 breach date and July 27 report date; the department publishes these samples when more than 500 California residents received notice. Stack Sports did not disclose an exact total or a complete geographic distribution.

Potentially affected fields were cardholder name, payment-card number, expiration date and CVV, plus checking-account number for some eCheck or ACH users. Stack Sports said account credentials, profile information, uploaded documents, Social Security numbers and driver’s license numbers were not involved.

Disclosure posture

Utah Youth Soccer issued the first public warning June 19 after member fraud reports, while Stack Sports was still investigating. The association relayed Stack Sports’ breach confirmation and restoration statement June 24. Stack Sports later finalized its review of impacted transactions and mailing addresses July 17 and issued consumer notices dated July 27, offering 24 months of identity-protection services.

The consumer notice says Stack Sports did not believe the incident constituted a breach under certain applicable laws but notified affected people so they could protect their information. That legal qualification does not negate the company’s factual findings about unauthorized checkout code and potentially affected payment data.

Current status

The operational disruption is resolved. Stack Sports reported clearing residual capture-code elements by June 22, and Utah Youth Soccer said June 24 that registration and payments could safely resume. The later affected-transaction review and notifications are breach-response milestones, not evidence that operational disruption continued.

Confidence and uncertainty

Confidence is high that malicious code captured payment data because Stack Sports directly described the code, the incident window and its removal. The evidence supports unauthorized access and malware as broad mechanisms, but it does not establish how the actor placed the code or first entered the environment.

Confidence is high that payment information was affected, although the notice uses potentially affected language for individual data fields. Parent reports of fraudulent charges provide corroborating misuse evidence, but the public record does not quantify confirmed fraudulent transactions. No evidence supports ransomware, extortion or a named threat actor.

Analytic gaps

The reviewed sources do not identify the initial access vector, exploited vulnerability, compromised credential, malicious-code family, actor infrastructure, responsible person or dwell time before May 8. They also do not disclose the total affected-person, transaction or card count; every affected customer organization or jurisdiction; or the amount of confirmed fraud.

No public forensic report explains how the unauthorized code was placed, whether captured data was transmitted directly to actor-controlled infrastructure or whether additional monitoring identified attempted recurrence.

Organizations involved

Impacted locations

Sources

Utah Soccer halts registration amid card charge reports

DysruptionHub reported that Utah Youth Soccer disabled player and administrator registration through Sports Connect after members reported potential unauthorized credit-card charges following recent registrations. At publication, Sports Connect said it was not aware of a breach and was investigating.

Sports Connect Credit Card Update

Utah Youth Soccer relayed Stack Sports’ confirmation that card information transmitted between certain end-user systems and Sports Connect Association payment functionality was affected. Stack Sports said the source was interrupted and remediated, all affected systems were restored, stored account data did not appear affected, and it was compiling an affected-person list and arranging notifications and protection services.

Utah Soccer warns families of potential data breach

FOX 13 reported that Utah families could not register after Sports Connect was taken offline for player and administrator registration. Interviewed parents described fraudulent card use after registration, including one nearly $300 out-of-state charge and multiple parents on one team replacing cards.

Utah Youth Soccer on Sports Connect

Stack Sports describes Sports Connect as supporting Utah Youth Soccer registration, online payments, payment plans, reminders, reporting and financial management. The page confirms the vendor-customer platform relationship relevant to the disrupted registration and payment workflow.

Notice of Data Breach

Stack Sports said it detected suspicious Sports Affinity activity June 8, determined unauthorized activity began about May 8, removed malicious checkout-capture code from its servers by June 10 and cleared residual browser-cache elements June 22. Potentially affected data included cardholder names, card numbers, expiration dates, CVVs and some checking-account numbers; the affected-transaction review finished July 17 and notices were dated July 27.

Submitted Breach Notification Sample: SPay Inc dba Stack Sports

The California Department of Justice record identifies SPay Inc. d/b/a Stack Sports and lists May 8, 2026 as the breach date. The department’s breach list shows a July 27 report date and explains that listed sample notices are submitted when more than 500 California residents received notice.

Stack Sports notifies users of payment card data exposure

SC Media reported that Stack Sports found malicious Sports Affinity checkout code dating to about May 8, removed it June 10 and cleared residual elements June 22. The brief listed potentially exposed card fields and checking-account numbers and reported the offer of 24 months of IDX identity-protection services.

About Us

Stack Sports describes a connected ecosystem of sports-specific software and services for governing bodies, clubs, leagues, teams, athletes, families and administrators. Its products cover sports management, registration, communications, payments, events and other participant services across domestic and international markets.

See something that needs correction?

Signed-in members can report an error, update, or missing source.