Clustered 3 filings across 3 jurisdictions · filing window Mar 15, 2022 → Mar 18, 2022. View entity profile → Other incidents for this victim →
incident inc_9ac150f09151403e · merge_method deterministic · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
Identity (basic) · Financial account · Financial credentials
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
DE ME NH
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Sep 1, 2021 → Feb 2, 2022
When the intrusion reportedly occurred, per the linked filings
Feb 2, 2022
Reported by DELAWARE AG filing
Feb 15, 2022
Reported by MAINE AG filing
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Penn LLC d/b/a Pulse TV issued a supplemental data security notice regarding a malware attack on its website hosted by third-party vendor Freestyle Solutions, Inc. The incident, discovered on February 2, 2022, affected customer payment card data (including CVV) between September 1, 2021, and February 2, 2022. Pulse TV alerted the vendor, disabled the malware, and implemented remediation steps including 2FA, EDR tools, and a new payment system. The notice covers residents in multiple states.
PulseTV, a subsidiary of Penn LLC, reported a data breach that affected its customers. The breach was caused by a malware attack on a webserver hosted and maintained by Freestyle Solutions, a third-party vendor that hosts PulseTV's website. The malware captured customers' payment card data between November 2019 and February 2022. This notification is a supplement to previous notices, adding 127 Maine residents to the list of those affected.
Affected (this filing): 127
Penn LLC d/b/a PulseTV submitted a supplemental breach notification to the New Hampshire Attorney General on March 18, 2022, supplementing a prior notice from January 24, 2022. The incident involved unauthorized access to the PulseTV website starting March 8, 2021, resulting in the compromise of credit card information for 1,148 New Hampshire residents. Visa alerted PulseTV to potential unauthorized transactions, leading to the discovery of the breach. Affected individuals were offered credit monitoring services.
Affected (this filing): 1,148