Clustered 5 filings across 4 jurisdictions · filing window Jan 14, 2022 → Mar 15, 2022. View entity profile → Other incidents for this victim →
incident inc_f59ea366a1b1439e · merge_method human · confidence 100%
Discovered → first regulatory filing
Range of discovered_at dates across filings
CA DE OR SC
Time between earliest and latest filing
Not recorded for this incident
Leak precedence · Materiality delta · SEC filing delay — no leak-site claim in this cluster; no SEC 8-K in this cluster.
all State AG
Earliest sighting first · deep chronology in Litigation Timeline
Nov 1, 2019 → Aug 31, 2021
When the intrusion reportedly occurred, per the linked filings
Mar 8, 2021
Reported by CALIFORNIA AG, SOUTH CAROLINA AG filings
Dec 2, 2021
Reported by OREGON AG filing
Feb 2, 2022
Reported by DELAWARE AG, CALIFORNIA AG filings
Penn LLC d/b/a Pulse TV issued a supplemental breach notification regarding a malware attack on its third-party web hosting vendor, Freestyle Solutions, Inc. The incident occurred between September 1, 2021, and February 2, 2022, compromising customer payment card data (numbers, expiration, CVV), names, addresses, and emails. Pulse TV alerted the vendor, disabled the malware, and engaged forensic investigators and legal counsel. Remediation includes implementing MFA, deploying endpoint detection, and migrating payment systems.
About this clustering
DisclosureLens links filings into incidents through layered matchers: deterministic rules (same source document, multistate filings of one breach, tight-window same-victim pairs), a weighted-similarity scorer for cross-source candidates, and an operator review queue for everything uncertain. Each link records its own method and confidence — shown per filing in the timeline below. The system defaults to NOT merging when uncertain, because a false merge (collapsing two unrelated breaches) is more harmful than a false split (showing related filings separately); uncertain pairs route to human review instead of auto-merging. Filing summaries shown in the timeline are AI-generated extracts — verify each against its linked source.
Penn LLC d/b/a Pulse TV reported a data breach to the Oregon Attorney General. The breach was reported on 2022-01-14. The breach occurred during 11/1/2019 - 8/31/2021. The breach was discovered on 12/2/2021. 201,000 individuals were affected. Notice was sent on 1/14/2022.
Affected (this filing): 201,000
Penn LLC d/b/a Pulse TV issued a supplemental data security notice regarding a malware attack on third-party vendor Freestyle Solutions, Inc. The incident involved unauthorized capture of customer payment card data (including CVV) from September 1, 2021, to February 2, 2022. The malware was hosted on Freestyle's webserver. Pulse TV alerted the vendor, who disabled the malware. Remediation includes adding 2FA, deploying EDR tools, and migrating payment systems. The notice covers residents of multiple states including Delaware, NY, and MD.
Penn LLC d/b/a Pulse TV notified California regulators of a data security incident involving unauthorized credit card transactions on pulsetv.com. The breach affected customers who purchased products between November 1, 2019, and August 31, 2021. Compromised data included names, addresses, emails, and payment card details (numbers, expiration, CVV). PulseTV engaged cybersecurity experts and law enforcement, implemented 2FA, and migrated payment systems.
Penn LLC (d/b/a PulseTV) notified customers of a data security incident involving unauthorized credit card transactions on its website. The compromise period was November 1, 2019, to August 31, 2021. Affected data included names, addresses, emails, and payment card details (number, expiration, CVV). PulseTV engaged cybersecurity experts and legal counsel, implemented 2FA, EDR tools, and migrated payment systems.