DisclosureLens
MalwareRetail & ConsumerRetailRansomwareData ExfiltratedData EncryptedSupply Chain (3P Vendor)Customer Data InvolvedPIIIdentity (basic)Financial accountFinancial credentialsLowContained

Penn, LLC

bd_5fb463d40ca02c44 · schema v1 · pii pii-v1

Severity

Low

Discovered

Feb 2, 2022

Filed

Mar 18, 2022

To disclose

6 weeks

Affected

193state residents only

Linked

3 filings

Confidence

66%
Full breach record for Penn, LLC6 incidents on file

Penn LLC d/b/a PulseTV submitted a supplemental notice to the New Hampshire Attorney General regarding a malware attack on its webserver hosted by third-party vendor Freestyle Solutions. The incident compromised credit card data (including CVV) for 193 New Hampshire residents between September 1, 2021, and February 2, 2022. PulseTV engaged forensic investigators, disabled the malware, and implemented MFA and EDR tools.

Incident timeline

undetected · 154 days
discovery → filing · 6 weeks / 44 days

Sep 1, 2021

Begins

Feb 2, 2022

Discovered

Mar 18, 2022

Filed

vs. sector median

1 wks faster

This filing is one of 3 about the same incident.View merged incident
Part of FreeStyle Solutions supply-chain incident (2022) — a supply-chain cascade affecting multiple organizations.View cascade →

Linked disclosures

Why this link?

Regulatory filings (2) · sorted by filing gap

Filing propagation · 3 filings · 3 states

View merged incident ↗
Delaware State AGMar 15 · first
Maine State AGMar 15 · first
New Hampshire State AG+3d · this page

Evidence ladder

Leak-site claim

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filingThis record

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.