HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTLowContained
Penn, LLC
bd_1f86650296908cc1 · schema v1 · pii pii-v1
Full breach record for Penn, LLC →Penn LLC d/b/a Pulse TV notified California regulators of a data security incident involving unauthorized credit card transactions on pulsetv.com. The breach affected customers who purchased products between November 1, 2019, and August 31, 2021. Compromised data included names, addresses, emails, and payment card details (numbers, expiration, CVV). PulseTV engaged cybersecurity experts and law enforcement, implemented 2FA, and migrated payment systems.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_758e0a44c15a009cSouth Carolina State AGfiled 2022-01-25Verified
- bd_88d3fe5c5ffe624aDelaware State AGfiled 2022-01-24(1d gap)Verified
- bd_2da599b0d158b3feOregon State AGfiled 2022-01-14(11d gap)Candidate
- bd_7f255a5dfe84e7ecCalifornia State AGfiled 2022-03-15(49d gap)Verified by operator
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-550280
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 25, 2022
- Raw hash
- 8c0510d6e15c4c2596b460bd94b4065aaf39feb068a643a9dc4a23b43e73d131
Reporting entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Victim entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Incident
- Discovered
- Mar 8, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified VISA and MasterCardProviding notice of this incident to appropriate state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 46 weeks(323 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.