Data Breaches

Nintendo Data Stolen in Third-Party Cyberattack

June 21, 2026 04:10 · 10 min read
Nintendo Data Stolen in Third-Party Cyberattack

Nintendo Confirms Data Breach in Third-Party Service

Nintendo of America has confirmed that threat actors stole internal survey data from the third-party TinyPulse service used for employee surveys. The company stated that its systems were not compromised and no personal customer or financial data was accessed.

The data involved is limited to internal survey content comprising a small subset of employees, and most of the information dates back several years. Nintendo is working with the service provider to address the issue.

Shadowbyt3$ Threat Actor Demands Ransom

The Shadowbyt3$ threat actor, which claims to have stolen close to 1GB of data from Nintendo, is demanding a ransom payment of $2 million. The group claims that the stolen data includes employee personal details, such as full names, email addresses, and bank statements.

However, Nintendo states that the incident only exposed survey information, and customer data remained unaffected. The company did not provide further details on the incident, but confirmed that it is working with the service provider to address the issue.

TinyPulse Service and WebMD Health Services

TinyPulse is an employee engagement and feedback platform used for anonymous employee surveys, engagement analytics, feedback collection, and workplace culture assessments. The service is owned by WebMD Health Services, which did not respond to requests for comment on the incident.

Nintendo of America is a subsidiary of the Japanese game company, responsible for operations in the United States, Canada, and parts of Latin America. The company uses TinyPulse for internal employee surveys, but it is not clear how the threat actors gained access to the service.

Shadowbyt3$ Threat Actor and Extortion Tactics

Shadowbyt3$ is a relatively new threat actor that describes itself as an "extortion as a service group" operating since October 2025. The group is known for leaking data stolen from victim companies that do not pay a ransom, and claims that in the case of a settlement, all data "will be Deleted Permanently and you will not hear from us again."

However, law enforcement strongly discourages paying the hackers, as it incentivizes future attacks and there is no guarantee that the threat actor will not privately sell the information. Nintendo has not commented on whether it will pay the ransom or engage in negotiations with the threat actor.

Impact and Response

The incident highlights the importance of securing third-party services and ensuring that employee data is protected. Nintendo has stated that it is working with the service provider to address the issue, but it is not clear what measures will be taken to prevent similar incidents in the future.

Customers and employees are advised to be vigilant and monitor their accounts for any suspicious activity. However, Nintendo has confirmed that customer data remained unaffected by the breach, and account holders do not need to take any action.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free