2026 Nintendo of America — TinyPulse employee survey data stolen (confirmed); ShadowByte$ extortion
Data compromised
Limited internal employee survey content for a small subset of Nintendo of America employees—most data years old; no customer or financial data per Nintendo
Technical writeup
ShadowByte$ claimed June 13, 2026 to have stolen ~859MB of Nintendo data via TinyPulse employee-engagement software, demanding $2M. On June 16–19, 2026 Nintendo of America confirmed to BleepingComputer and gaming press that TinyPulse—a WebMD Health Services subsidiary used for internal employee surveys—was compromised. Nintendo stated its own systems were not breached, no customer or financial data was accessed, and exposed data is limited to internal survey content for a small subset of employees—mostly years old. ShadowByte$ claims broader HR artifacts (W-9s, bank statements); Nintendo has not attested that scope. Customer accounts require no action.
Root cause
Third-party TinyPulse (WebMD Health Services) compromise; Nintendo systems not breached
References
- https://www.bleepingcomputer.com/news/security/nintendo-confirms-data-stolen-in-webmd-subsidiary-cyberattack/
- https://mashable.com/tech/nintendo-data-breach-statement-tiny-pulse-ransomware
- https://nintendoeverything.com/nintendo-issues-statement-about-recent-data-breach/
- https://cybernews.com/security/nintendo-employee-data-ransom-claim/
- https://www.nintendolife.com/news/2026/06/hacker-group-claims-to-have-stolen-nintendo-data-posts-usd2-million-ransom