HomeSecurityNintendo: Employee data breach via third-party provider

Nintendo: Employee data breach via third-party provider

Nintendo of America has confirmed that it is investigating a security incident related to the TinyPulse, a third-party service used internally for employee surveys and evaluations. The company clarified that its own information systems were not compromised and that no personal customer information or financial data was accessed.

Nintendo Data Breach

The case came to light following claims by cyber-extortion group Shadowbyt3$, which claims to have gained access to sensitive information related to Nintendo of America employees and is demanding a ransom of $2 million.

Nintendo's position on the incident

In an official statement, Nintendo said it is aware of the TinyPulse and that the data affected is limited to internal employee survey content, which concerns a small portion of its staff. At the same time, the company emphasized that most of the information that may have been exposed dates back several years.

The Japanese company's American subsidiary is responsible for Nintendo's operations in the United States, Canada and parts of Latin America, which makes any security incident particularly significant due to its large operational scale.

See also: Kodak: ShinyHunters behind data breach?

What is the TinyPulse platform?

TinyPulse is a popular employee experience management platform used by businesses to conduct anonymous surveys, collect feedback, evaluate company culture, and measure employee satisfaction.

Platforms of this type often manage information that, while not considered particularly sensitive at the customer level, may include internal business data, personal employee opinions, contact information , or even information that could be used in future social engineering attacks.

Nintendo said it is working closely with the service provider to assess the extent of the incident and take the necessary measures.

The claims of the Shadowbyt3$ group

The picture presented by the Shadowbyt3$ group is significantly more worrying. The perpetrators claim to have extracted approximately 1 GB of data and have given the company 48 hours to enter into negotiations before releasing the content publicly.

Nintendo: Employee data breach via third-party provider

According to their claims, the records include full employee names, email addresses, reporting and research data, bank statements, W-9 tax forms with employee identifiers, as well as internal reports and progress plans covering a period from 2016 to 2026.

The cybercriminals state that if the company contacts them, they are willing to extend the deadline for another day, insisting on the demand for a ransom payment of two million dollars.

See also: Hacker group claims to have breached Novo Nordisk and demands $25 million

Another example of supply chain attacks

The incident highlights a growing trend in cybersecurity: attacks via third-party service providers. Large enterprises invest significant amounts in protecting their core systems, but attackers often choose to target external partners who have access to data or business processes.

This strategy allows attackers to exploit potential weaknesses in smaller or less protected organizations, using them as an indirect entry point into larger companies and well-known brands.

Nintendo: Employee data breach via third-party provider

Why paying ransom remains a dangerous option

Despite assurances from extortion groups that data will be deleted after payment, law enforcement strongly discourages any payment. There is no guarantee that the attackers will keep their promises or that the stolen data will not be resold to other criminals later.

Shadowbyt3$ is a relatively new cyber extortion group, active since October 2025 and describing itself as an “extortion as a service group.” Its emergence confirms that the cybercrime ecosystem continues to evolve, with new groups adopting business models based on data leakage and financial pressure on victims.

See also: iRhythm reveals data breach

While there is no evidence so far that any Nintendo customer accounts have been affected, the incident is a reminder that even the largest technology companies remain exposed to the risks that arise from their broader ecosystem of partners and suppliers.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS