HackingStolen CredentialsTargetedData ExfiltratedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Penn, LLC
bd_758e0a44c15a009c · schema v1 · pii pii-v1
Full breach record for Penn, LLC →Penn LLC (d/b/a PulseTV) notified customers of a data security incident involving unauthorized credit card transactions on its website. The compromise period was November 1, 2019, to August 31, 2021. Affected data included names, addresses, emails, and payment card details (number, expiration, CVV). PulseTV engaged cybersecurity experts and legal counsel, implemented 2FA, EDR tools, and migrated payment systems.
This filing is one of 6 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (5) · sorted by filing gap
- bd_1f86650296908cc1California State AGfiled 2022-01-25Verified by operator
- bd_88d3fe5c5ffe624aDelaware State AGfiled 2022-01-24(1d gap)Verified
- bd_b1f86ecba6b26257New Hampshire State AGfiled 2022-01-27(2d gap)Verified
- bd_2da599b0d158b3feOregon State AGfiled 2022-01-14(11d gap)Candidate
Show 1 more filing ↓Show fewer ↑up to 49d gap
- bd_7f255a5dfe84e7ecCalifornia State AGfiled 2022-03-15(49d gap)Verified by operator
Source provenance
- Source URL
- https://consumer.sc.gov/sites/consumer/files/Documents/Business%20Resources%20Laws/Related%20Laws/Breaches/2022/PennLLCPulseTV.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 25, 2022
- Raw hash
- 533c14532e9bb147dcb8cf4b858d3ea6179f2ff0c9bacc63c7d782839ba774ce
Reporting entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Victim entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Incident
- Discovered
- Mar 8, 2021
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing ApplicationT1056 Input Capture
- Threat actor
- ExternalFinancial
- Regulator citations
- law enforcement contacted us regarding additional payment card compromises
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 46 weeks(323 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.