Penn, LLC
ent_019e233515f7f754bc0d85f3831b4900
Disclosures
14
State AG · HHS OCR · 9 jurisdictions
Incidents
3
filings grouped by incident
Max affected reported
201,000
as filed · State AG OR
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Penn, LLC
- Normalized
- penn— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DM94O8FKJ0US12
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (14)newest first
- ⛰️New Hampshire State AGas victim2022-03-18
Penn LLC d/b/a PulseTV submitted a supplemental breach notification to the New Hampshire Attorney General on March 18, 2022, supplementing a prior notice from January 24, 2022. The incident involved unauthorized access to the PulseTV website starting March 8, 2021, resulting in the compromise of credit card information for 1,148 New Hampshire residents. Visa alerted PulseTV to potential unauthorized transactions, leading to the discovery of the breach. Affected individuals were offered credit monitoring services.
- 💎Delaware State AGas victim2022-03-15
Penn LLC d/b/a Pulse TV issued a supplemental data security notice regarding a malware attack on its website hosted by third-party vendor Freestyle Solutions, Inc. The incident, discovered on February 2, 2022, affected customer payment card data (including CVV) between September 1, 2021, and February 2, 2022. Pulse TV alerted the vendor, disabled the malware, and implemented remediation steps including 2FA, EDR tools, and a new payment system. The notice covers residents in multiple states.
- 🐻California State AGas victim2022-03-15
Penn LLC d/b/a Pulse TV issued a supplemental breach notification regarding a malware attack on its third-party web hosting vendor, Freestyle Solutions, Inc. The incident occurred between September 1, 2021, and February 2, 2022, compromising customer payment card data (numbers, expiration, CVV), names, addresses, and emails. Pulse TV alerted the vendor, disabled the malware, and engaged forensic investigators and legal counsel. Remediation includes implementing MFA, deploying endpoint detection, and migrating payment systems.
- 🦞Maine State AGas victim2022-03-15
PulseTV, a subsidiary of Penn LLC, reported a data breach that affected its customers. The breach was caused by a malware attack on a webserver hosted and maintained by Freestyle Solutions, a third-party vendor that hosts PulseTV's website. The malware captured customers' payment card data between November 2019 and February 2022. This notification is a supplement to previous notices, adding 127 Maine residents to the list of those affected.
- 🐻California State AGas victim2022-01-25
Penn LLC d/b/a Pulse TV notified California regulators of a data security incident involving unauthorized credit card transactions on pulsetv.com. The breach affected customers who purchased products between November 1, 2019, and August 31, 2021. Compromised data included names, addresses, emails, and payment card details (numbers, expiration, CVV). PulseTV engaged cybersecurity experts and law enforcement, implemented 2FA, and migrated payment systems.
- 🌴South Carolina State AGas victim2022-01-25
Penn LLC (d/b/a PulseTV) notified customers of a data security incident involving unauthorized credit card transactions on its website. The compromise period was November 1, 2019, to August 31, 2021. Affected data included names, addresses, emails, and payment card details (number, expiration, CVV). PulseTV engaged cybersecurity experts and legal counsel, implemented 2FA, EDR tools, and migrated payment systems.
- 🦬Montana State AGas victim2022-01-24
Penn LLC dba PulseTV reported a data breach to the Montana Attorney General. The breach was reported on 2022-01-24. The breach occurred from 11/1/2019 to 8/31/2021. 602 Montana residents were affected.
- 💎Delaware State AGas victim2022-01-24
Penn LLC dba Pulse TV notified customers of a data security incident involving unauthorized credit card transactions on its website. The compromise period was November 1, 2019, to August 31, 2021. Affected data included names, addresses, emails, payment card numbers, expiration dates, and CVVs. PulseTV engaged cybersecurity experts and legal counsel, cooperated with law enforcement and card networks, and implemented remediation measures including 2FA, EDR tools, and a new payment system.
- 🦞Maine State AGas victim2022-01-24
Penn LLC, doing business as Pulse TV, reported a data breach that appears to be an external system breach, though it could not be confirmed. The breach occurred between November 1, 2019, and August 31, 2021, and was discovered on December 2, 2021. The compromised information includes financial account numbers or credit/debit card numbers in combination with security codes, access codes, passwords, or PINs. This notice is a supplement to a previous notification, with the total number of affected Maine residents updated to 753.
- 💎Delaware State AGas victim2022-01-24
Penn LLC d/b/a Pulse TV issued a supplemental data security notice regarding a malware attack on third-party vendor Freestyle Solutions, Inc. The incident involved unauthorized capture of customer payment card data (including CVV) from September 1, 2021, to February 2, 2022. The malware was hosted on Freestyle's webserver. Pulse TV alerted the vendor, who disabled the malware. Remediation includes adding 2FA, deploying EDR tools, and migrating payment systems. The notice covers residents of multiple states including Delaware, NY, and MD.
- 🦫Oregon State AGas victim2022-01-14
Penn LLC d/b/a Pulse TV reported a data breach to the Oregon Attorney General. The breach was reported on 2022-01-14. The breach occurred during 11/1/2019 - 8/31/2021. The breach was discovered on 12/2/2021. 201,000 individuals were affected. Notice was sent on 1/14/2022.
- 🌲Washington State AGas victim2021-12-30
Penn LLC d/b/a PulseTV, a business sector entity reported a malware incident to the Washington Attorney General. The organization became aware of the incident on 2021-10-10 and filed notice on 2021-12-30. 4,302 Washington residents were affected. 81 days elapsed between awareness and notification. 709 days to identify the breach. 0 days to contain the breach.
- 🦞Maine State AGas victim2021-12-30
Pulse TV, a Tinley Park, IL-based provider, reported an external system breach occurring between November 1, 2019, and August 31, 2021, discovered on December 2, 2021. The incident affected approximately 201,000 individuals, including 730 Maine residents. Acquired data included names, personal identifiers, and financial account or credit/debit card numbers (with security codes/PINs). Pulse TV sent written notifications to affected consumers on December 30, 2021, but did not offer identity theft protection services.
- PAHHS OCRas reporting2021-06-29
Penn Foundation (also identified as Penn Foundation – St. Luke's Health Network), a healthcare provider in PA, reported to HHS OCR on 2021-06-29 a ransomware attack affecting 768 individuals. Breached information was located on a network server. PHI involved included names, dates of birth, addresses, Social Security numbers, diagnoses, and financial and treatment information. The CE notified HHS, affected individuals, and media, offered credit monitoring, and established a call center and website. Additional administrative and technical safeguards were implemented.