HackingStolen CredentialsData ExfiltratedCustomer Data InvolvedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowActive
Penn, LLC
bd_64f99c9c7e03f092 · schema v1 · pii pii-v1
Full breach record for Penn, LLC →Penn LLC dba Pulse TV notified customers of a data security incident involving unauthorized credit card transactions on its website. The compromise period was November 1, 2019, to August 31, 2021. Affected data included names, addresses, emails, payment card numbers, expiration dates, and CVVs. PulseTV engaged cybersecurity experts and legal counsel, cooperated with law enforcement and card networks, and implemented remediation measures including 2FA, EDR tools, and a new payment system.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/02/PulseTV-Individual-Notice-Template-Letter.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 24, 2022
- Raw hash
- d254b61b97c3a780fc66276ae337eb0f232576a0ea0c619669b7502042bc7032
Reporting entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Victim entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Incident
- Discovered
- Mar 8, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- ExternalFinancial
- Regulator citations
- providing notice of this incident to appropriate state regulators
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 46 weeks(322 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.