Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes. PulseTV disclosed a payment-card incident that may have exposed customer information. The initial notice put the affected population at approximately 201,000; a later Maine supplemental notice revised the overall count to 227,769 and attributed the incident to malware on a webserver hosted and maintained by vendor Freestyle Solutions.

What happened in the PulseTV breach?

PulseTV, operated by Penn LLC, disclosed that customer payment-card information may have been compromised through its website. The account developed in stages: at first, PulseTV said the investigation could not confirm that the website caused the unauthorized transactions. A later Maine supplemental notice reported that investigators found malware on a webserver hosted and maintained by Freestyle Solutions, which hosted PulseTV’s website. The notice said the malware captured customer card data and saved it on Freestyle’s systems.

That later finding gives a clearer explanation of the incident, but the notices describe potential exposure; they do not establish that every affected person’s information was stolen or that every card was used fraudulently.

How many people were affected?

The number changed as the investigation and notifications progressed. Maine’s initial filing reported approximately 201,000 affected people, including 730 Maine residents. The supplemental notice later reported 227,769 people overall. It listed 753 Maine residents for the original incident period and 127 Maine residents for the newly identified September 1, 2021–February 2, 2022 period.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The roughly 200,000 figure in the original headline reflects the initial reporting, not the later overall count.

What information may have been exposed?

The notices identified payment-card numbers, expiration dates and security codes, as well as names, addresses and email addresses. The filings classified the information as personal identifiers combined with financial-account or payment-card information and a security or access code. Exposure was described as possible; the notices do not say that every listed data element was exposed for every person.

When did the incident take place?

The reported period was extended as investigators learned more. California’s breach notice record listed November 1, 2019–August 31, 2021; the later Maine notice extended the potential compromise period through February 2, 2022.

Date What the notices and reporting said
March 2021 SecurityWeek reported that PulseTV said Visa first alerted it to suspicious activity. The company scanned for malware and performed other checks but did not find an ongoing compromise then.
Fall 2021 Law enforcement later notified PulseTV of additional payment-card compromises that appeared to originate from its website. In late November, an investigation identified the site as a common point of purchase for unauthorized Mastercard transactions.
December 2, 2021 Maine’s initial filing recorded this as the discovery date and said the cause could not be confirmed based on the information then available.
December 30, 2021 The initial written notices were reported. Maine’s filing listed approximately 201,000 people overall and 730 Maine residents.
February 2, 2022 The later investigation identified malware on the vendor-hosted webserver. The supplemental notice said the malware captured card data and stored it in a file on Freestyle Solutions’ systems.
February 15, 2022 Maine’s supplemental filing said a PCI-DSS forensic investigator confirmed that the potential compromise period ended on this date.
March 15–17, 2022 The supplemental filing recorded another round of written notifications and gave the revised overall count of 227,769.

What should affected PulseTV customers do?

If you purchased from PulseTV during the reported period, use any notice you received to determine whether your information was included. If you see a transaction you do not recognize, contact the card issuer using the number on your card or its official website; the issuer can explain options such as replacing the card and monitoring the account.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Review card and bank statements for unfamiliar charges and report suspicious activity promptly.
  • Be alert for unexpected emails or calls that claim to be about the incident. Do not share passwords, verification codes or full card details in response to an unsolicited message.
  • If you have questions about personal-information requests, PulseTV’s current policy page lists a request form and privacy contact. Current contact details can change, so check the company’s page directly.

Maine’s initial and supplemental filings say identity-theft protection services were not offered to affected customers. The notices reviewed do not establish a dedicated current response channel for this historical incident.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What security measures did PulseTV report?

In January 2022, SecurityWeek reported that PulseTV described adding two-factor authentication on internal devices, using endpoint detection and response tools, and migrating to a different payment system. Those were measures reported at that time; they are not independent verification of the company’s current security controls. PulseTV’s current policy page describes general physical, electronic and managerial safeguards, but that policy language does not establish which controls were in place during the incident.

Sources

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.