Update — June 19, 2026: Nintendo of America confirmed to BleepingComputer that threat actors stole data from third-party TinyPulse (a WebMD Health Services employee-engagement platform) used for internal surveys. Nintendo’s own systems were not compromised and no customer or financial data was accessed.
What Nintendo confirmed
Nintendo stated exposed data is “limited to internal survey content comprising a small subset of our employees, and most of the information dates back several years.” Only Nintendo of America employees who used TinyPulse appear affected—not global Nintendo divisions.
ShadowByte$ extortion context
On June 13 the ShadowByte$ group claimed ~859MB including W-9 forms and bank statements and demanded $2M. Nintendo has not attested that broader actor scope—only survey content per its official statement. Customer game accounts require no action.
Employee guidance
- Do not download alleged leak archives.
- Watch for HR impersonation using old survey content.
- Enable MFA on work email; rotate passwords if reused on personal accounts.
Canonical record: Nintendo TinyPulse 2026 on BreachHistory.
Sources: BleepingComputer, Nintendo Everything