MalwareRansomwareData ExfiltratedSupply Chain (3P Vendor)Customer Data InvolvedPIIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALSLowContained
Penn, LLC
bd_88d3fe5c5ffe624a · schema v1 · pii pii-v1
Full breach record for Penn, LLC →Penn LLC d/b/a Pulse TV issued a supplemental data security notice regarding a malware attack on third-party vendor Freestyle Solutions, Inc. The incident involved unauthorized capture of customer payment card data (including CVV) from September 1, 2021, to February 2, 2022. The malware was hosted on Freestyle's webserver. Pulse TV alerted the vendor, who disabled the malware. Remediation includes adding 2FA, deploying EDR tools, and migrating payment systems. The notice covers residents of multiple states including Delaware, NY, and MD.
This filing is one of 5 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (4) · sorted by filing gap
- bd_1f86650296908cc1California State AGfiled 2022-01-25(1d gap)Verified by operator
- bd_758e0a44c15a009cSouth Carolina State AGfiled 2022-01-25(1d gap)Verified
- bd_2da599b0d158b3feOregon State AGfiled 2022-01-14(10d gap)Candidate
- bd_7f255a5dfe84e7ecCalifornia State AGfiled 2022-03-15(50d gap)Verified by operator
Source provenance
- Source URL
- https://attorneygeneral.delaware.gov/wp-content/uploads/sites/50/2022/03/PulseTV-Ad-Repeat-Notice-r3prf_FINAL-PROOF-ROUND-II.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 24, 2022
- Raw hash
- b9139d2ea98d19e8d6b81d502fa537a71b66cc1afc948009c3bfc476aa5f56e2
Reporting entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Victim entity
- Name
- Penn, LLCnorm: penn
- Domain
- pulsetv.com
Incident
- Discovered
- Feb 2, 2022
- Materiality determined
- —
- Notification sent
- Mar 1, 2022
- Affected individuals
- Not disclosed
- Data types
- PIIIDENTITY_BASICFINANCIAL_ACCOUNTFINANCIAL_CREDENTIALS
- Attack vector
- Ransomware
- MITRE ATT&CK
- T1486 Data Encrypted for ImpactT1119 Automated Collection
- Threat actor
- ExternalFinancial
- Regulator citations
- Providing notice of this incident to appropriate state regulators
- Initial access
- supply_chain
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.