DisclosureLens
MalwareRetail & ConsumerRetailRansomwareSupply Chain (3P Vendor)Customer Data InvolvedData ExfiltratedIdentity (basic)Financial accountFinancial credentialsLowContained

Penn, LLC

bd_5ae0a6102d57b514 · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 2, 2022

Filed

Mar 15, 2022

To disclose

6 weeks

Affected

Not disclosed

Linked

3 filings

Confidence

66%
Full breach record for Penn, LLC6 incidents on file

Penn LLC d/b/a Pulse TV issued a supplemental data security notice regarding a malware attack on its website hosted by third-party vendor Freestyle Solutions, Inc. The incident, discovered on February 2, 2022, affected customer payment card data (including CVV) between September 1, 2021, and February 2, 2022. Pulse TV alerted the vendor, disabled the malware, and implemented remediation steps including 2FA, EDR tools, and a new payment system. The notice covers residents in multiple states.

Incident timeline

undetected · 154 days
discovery → filing · 6 weeks / 41 days

Sep 1, 2021

Begins

Feb 2, 2022

Discovered

Mar 15, 2022

Filed

vs. sector median

2 wks faster

This filing is one of 3 about the same incident.View merged incident
Part of FreeStyle Solutions supply-chain incident (2022) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Maine State AGMar 15 · first
Delaware State AGMar 15 · first · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.