Penn, LLC
ent_019e233515f7f754bc0d85f3831b4900
Disclosures
17
State AG · HHS OCR · 12 jurisdictions
Multi-filing incidents
4
incidents joining 2+ filings here
Max affected reported
227,769
nationwide · State AG IN
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Penn, LLC
- Normalized
- penn— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300DM94O8FKJ0US12
- SEC EDGAR CIK
- None — not an SEC registrant
- Domain
- None on record
Disclosure history (17)newest first
- New Hampshire State AGas victim2022-03-18
Penn LLC d/b/a PulseTV submitted a supplemental notice to the New Hampshire Attorney General regarding a malware attack on its webserver hosted by third-party vendor Freestyle Solutions. The incident compromised credit card data (including CVV) for 193 New Hampshire residents between September 1, 2021, and February 2, 2022. PulseTV engaged forensic investigators, disabled the malware, and implemented MFA and EDR tools.
- Delaware State AGas victim2022-03-15
Penn LLC d/b/a Pulse TV issued a supplemental data security notice regarding a malware attack on its website hosted by third-party vendor Freestyle Solutions, Inc. The incident, discovered on February 2, 2022, affected customer payment card data (including CVV) between September 1, 2021, and February 2, 2022. Pulse TV alerted the vendor, disabled the malware, and implemented remediation steps including 2FA, EDR tools, and a new payment system. The notice covers residents in multiple states.
- California State AGas victim2022-03-15
Pulse TV (Penn LLC) disclosed a data breach affecting customers who made purchases between September 1, 2021, and February 2, 2022. The incident was caused by a malware attack on a webserver hosted by third-party vendor Freestyle Solutions, Inc. The malware captured payment card data, including card numbers, expiration dates, and CVVs, as well as names, addresses, and email addresses. Pulse TV discovered the specific cause on February 2, 2022, after an investigation initiated in March 2021. The company has disabled the malware, engaged forensic experts, and is implementing remediation measures including two-factor authentication and migrating payment systems.
- Maine State AGas victim2022-03-15
PulseTV, a subsidiary of Penn LLC, reported a data breach that affected its customers. The breach was caused by a malware attack on a webserver hosted and maintained by Freestyle Solutions, a third-party vendor that hosts PulseTV's website. The malware captured customers' payment card data between November 2019 and February 2022. This notification is a supplement to previous notices, adding 127 Maine residents to the list of those affected.
- New Hampshire State AGas victim2022-01-27
Penn LLC d/b/a PulseTV notified the NH Attorney General of a data security incident involving unauthorized credit card transactions on its website. The breach affected customers who purchased between Nov 1, 2019 and Aug 31, 2021. 1,148 NH residents were identified. Compromised data included names, addresses, emails, and full payment card details (number, expiration, CVV). PulseTV engaged cybersecurity experts and law enforcement, and implemented MFA and new payment systems.
- California State AGas victim2022-01-25
PulseTV (Penn LLC) notified customers of a data security incident involving potential compromise of credit card information. The incident window is Nov 1, 2019 to Aug 31, 2021. Discovery occurred on Mar 8, 2021, when VISA alerted the company to unauthorized transactions. Affected data includes names, addresses, emails, payment card numbers, expiration dates, and CVVs. The company engaged forensic experts, cooperated with law enforcement, and implemented remediation measures including 2FA, EDR tools, and migrating payment systems.
- Indiana State AGas victim2022-01-25
Penn LLC dba Pulse TV reported a data breach to the Indiana Attorney General. The breach occurred on 2019-11-01 and was reported on 2022-01-25. 4,028 Indiana residents were affected. 227,769 individuals affected in total.
- South Carolina State AGas victim2022-01-25
Penn LLC (d/b/a PulseTV) notified customers of a data security incident involving unauthorized credit card transactions on its website. The compromise period was November 1, 2019, to August 31, 2021. Affected data included names, addresses, emails, and payment card details (number, expiration, CVV). PulseTV engaged cybersecurity experts and legal counsel, implemented 2FA, EDR tools, and migrated payment systems.
- Massachusetts State AGas victim2022-01-25
Penn LLC d/b/a PulseTV reported a data breach to the Massachusetts Office of Consumer Affairs and Business Regulation. The breach was reported on 2022-01-25. 5,270 Massachusetts residents were affected. The report records the breach type as electronic.
- Montana State AGas victim2022-01-24
Penn LLC dba PulseTV notified customers of a data security incident involving unauthorized credit card transactions on its website. The compromise affected transactions between November 1, 2019, and August 31, 2021. Data potentially exposed includes names, addresses, emails, payment card numbers, expiration dates, and CVVs. PulseTV engaged legal counsel and cybersecurity experts, and implemented MFA and new endpoint detection tools.
- Delaware State AGas victim2022-01-24
Penn LLC dba Pulse TV notified customers of a data security incident involving unauthorized credit card transactions on its website. The compromise period was November 1, 2019, to August 31, 2021. Affected data included names, addresses, emails, payment card numbers, expiration dates, and CVVs. PulseTV engaged cybersecurity experts and legal counsel, cooperated with law enforcement and card networks, and implemented remediation measures including 2FA, EDR tools, and a new payment system.
- Maine State AGas victim2022-01-24
Penn LLC, doing business as Pulse TV, reported a data breach that appears to be an external system breach, though it could not be confirmed. The breach occurred between November 1, 2019, and August 31, 2021, and was discovered on December 2, 2021. The compromised information includes financial account numbers or credit/debit card numbers in combination with security codes, access codes, passwords, or PINs. This notice is a supplement to a previous notification, with the total number of affected Maine residents updated to 753.
- Oregon State AGas victim2022-01-14
Penn LLC d/b/a Pulse TV reported a data breach to the Oregon Attorney General. The breach was reported on 2022-01-14. The breach occurred during 11/1/2019 - 8/31/2021. The breach was discovered on 12/2/2021. 201,000 individuals were affected. Notice was sent on 1/14/2022.
- Illinois State AGas victim2022-01-01
PENN LLC filed a data-breach notice with the Illinois Attorney General during 2022 (case 2022-188). The register records the breach as discovered on February 2, 2022. Illinois does not publish the number of people affected — 815 ILCS 530/10 permits the Attorney General to publish only the entity name, the types of personal information and the date range.
- Washington State AGas victim2021-12-30
Penn LLC d/b/a PulseTV filed a supplemental notice with the Washington AG regarding a data breach affecting 3,603 Washington residents. Unauthorized credit card transactions occurred on pulsetv.com between Nov 1, 2019 and Aug 31, 2021. Affected data included names, addresses, emails, and payment card details (including CVV). PulseTV engaged cybersecurity experts and law enforcement, and implemented MFA and endpoint detection.
- Maine State AGas reporting2021-12-30
Pulse TV, a Tinley Park, IL-based provider, reported an external system breach occurring between November 1, 2019, and August 31, 2021, discovered on December 2, 2021. The incident affected approximately 201,000 individuals, including 730 Maine residents. Acquired data included names, personal identifiers, and financial account or credit/debit card numbers (with security codes/PINs). Pulse TV sent written notifications to affected consumers on December 30, 2021, but did not offer identity theft protection services.
- PENNSYLVANIAHHS OCRas reporting2021-06-29
Penn Foundation (also identified as Penn Foundation – St. Luke's Health Network), a healthcare provider in PA, reported to HHS OCR on 2021-06-29 a ransomware attack affecting 768 individuals. Breached information was located on a network server. PHI involved included names, dates of birth, addresses, Social Security numbers, diagnoses, and financial and treatment information. The CE notified HHS, affected individuals, and media, offered credit monitoring, and established a call center and website. Additional administrative and technical safeguards were implemented.
Supply-chain cascadesreviewed and confirmed
- Penn, LLC’s filing is one of at least 12 in the FreeStyle Solutions supply-chain incident (2022).