MalwareRansomwareData ExfiltratedData EncryptedCustomer Data InvolvedSupply Chain (3P Vendor)TargetedIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Penn, LLC
bd_7f255a5dfe84e7ec · schema v1 · pii pii-v1
Full breach record for Penn, LLC →Penn LLC d/b/a Pulse TV issued a supplemental breach notification regarding a malware attack on its third-party web hosting vendor, Freestyle Solutions, Inc. The incident occurred between September 1, 2021, and February 2, 2022, compromising customer payment card data (numbers, expiration, CVV), names, addresses, and emails. Pulse TV alerted the vendor, disabled the malware, and engaged forensic investigators and legal counsel. Remediation includes implementing MFA, deploying endpoint detection, and migrating payment systems.
California clockDiscovered Feb 2, 2022 → Notified Feb 2, 20220d ✓ CA 60-day OK6 weeks discovery → filing
⚠ notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1f86650296908cc1California State AGfiled 2022-01-25(49d gap)Verified by operator
- bd_758e0a44c15a009cSouth Carolina State AGfiled 2022-01-25(49d gap)Verified
- bd_88d3fe5c5ffe624aDelaware State AGfiled 2022-01-24(50d gap)Verified
- bd_2da599b0d158b3feOregon State AGfiled 2022-01-14(60d gap)Candidate
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-551702
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 15, 2022
- Raw hash
- f0533aa5e3f27559911633d13341f7655c77d5c339f4393696fcdb9288f7e50c
Reporting entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Victim entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Incident
- Discovered
- Feb 2, 2022
- Materiality determined
- —
- Notification sent
- Feb 2, 2022
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for Impact
- Threat actor
- ExternalFinancial
- Regulator citations
- Providing notice of this incident to appropriate state regulators
- Third party
- via Freestyle Solutions, Inc.
- Initial access
- supply_chain
Compliance
- Time to disclose
- 6 weeks(41 days from discovery to filing)
- Compliance flags
- CA 60-day OK · 0d
- Discovery-date grounding
- notification dateThe stored discovery date equals the NOTIFICATION date, collapsing the clock to ~zero. This UNDERSTATES the delay and can mask a real violation.
- Clock breakdown
Statute Window Elapsed Threshold Status California Discovered: Feb 2, 2022→ Notified: Feb 2, 20220d 60 days (analyst band, pre-2026 discoveries) CA 60-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.