Last Update: 08/01/2026 at 1:00 PM EST

Nintendo TinyPulse Employee Breach

Coverage from BleepingComputer, TechRadar, and others

Articles

21

Active Days

27

The Topic

Nintendo TinyPulse Employee Breach topic image

This topic centers on a third-party breach involving TinyPulse, an employee survey platform used by Nintendo of America, where internal employee data was reportedly stolen and used in an extortion attempt. Nintendo says its own systems and customer data were not compromised, but the incident still raises privacy risks for employees whose survey and HR-related information may have been exposed. The case highlights how vendor platforms can become the main path for sensitive data loss even when the target company’s internal network remains intact.

First Article: 06/15/26

Latest Article: 07/11/26

Summary

  • Nintendo of America says the issue was limited to TinyPulse, a third-party employee survey service, not Nintendo’s internal systems.
  • The disputed data set is described as employee survey and HR-related material, with some claims including names, emails, bank statements, and W-9 forms.
  • An extortion group reportedly demanded $2 million and threatened to leak the data.
  • Reporting consistently points to a vendor-side compromise or supply-chain exposure rather than a direct breach of Nintendo infrastructure.
  • Nintendo says no customer data or financial systems were affected, but employee privacy and identity-theft risk remain central concerns.
  • The incident places renewed attention on security controls around SaaS tools that store workplace feedback and other sensitive employee records.

History

06/22/2026

The story now more clearly frames the incident as an extortion-driven exposure of Nintendo employee data through TinyPulse, with new reporting pointing to additional identity and financial records beyond survey content. The main change is not a direct breach of Nintendo's core systems, but a stronger and broader allegation about what the vendor-held data may have included.

06/19/2026

The story has shifted from a loosely framed allegation of stolen Nintendo employee data to a more specific vendor-breach narrative, with Nintendo publicly narrowing the impact to limited internal employee survey content and denying customer-system compromise. The main new wrinkle is the stronger, repeated linkage to TinyPulse/WebMD Health Services and the clearer contrast between threat-actor theft claims and Nintendo's constrained account.

Featured

Timeline: 27 Days

Jun 15Jun 21Jun 25Jul 1Jul 5Jul 11

Additional Articles

⭐⭐⭐⭐⭐

Rescana06-21-2026
Nintendo of America confirmed on June 18, 2026 that TinyPulse SaaS was compromised and employee survey data was exfiltrated in a ransom extortion incident.
Tech Insider / Nadia Dubois07-11-2026
ShadowByt3$ extortion claims against TinyPulse in June 2026 led Nintendo of America to confirm theft of a subset of employee HR and financial-related records.

⭐⭐⭐

Mashable06-17-2026
Nintendo of North America reported a TinyPulse third-party issue after ransomware extortion claims, saying Nintendo systems were not compromised and customer data was not accessed.
Tech Times06-19-2026
Nintendo of America said Shadowbyt3$ targeted TinyPulse, a third-party HR survey platform, and released samples of stolen employee data.
Nintendowire / Peter Glagowski06-17-2026
Nintendo confirmed a TinyPulse third-party breach involving internal employee survey data, with reported $2 million ransom demand during ongoing investigation.
Freep06-17-2026
ShadowByt3$ demanded $2 million after claiming to steal TinyPulse employee feedback data used by Nintendo, with threats issued on June 13 and June 14.
VideogamesChronicle / Andy Robinson06-16-2026
ShadowBytes threatened Nintendo with a $2 million ransom demand over an alleged TinyPulse employee data breach in a dispute over breach scope and data age.
TechRepublic / Ken Underhill06-15-2026
ShadowByte$ allegedly extorted Nintendo with a $2 million demand after claiming theft of employee HR and engagement data, as Cybernews researchers reviewed leaked samples.
Nintendo Everything06-15-2026
A June 13, 2026 breach claim alleges SHADOWBYT3$ accessed about 859MB from TINYpulse systems used for Nintendo employee engagement data, with verification pending.
Nintendo Everything06-16-2026
Nintendo issued a statement in connection with a TinyPulse third-party breach after reported exposure claims involving Nintendo of America employee survey data.
TechNadu / Lore Apostol06-15-2026
Threat actor SHADOWBYT3$ claimed a Nintendo breach on June 13, 2026, alleging exposure of employee and financial data sourced from TINYpulse systems.
TechNadu06-15-2026
A threat actor using SHADOWBYT3$ claimed on June 13, 2026 that Nintendo data was stolen from TINYpulse systems, but confirmation is unavailable.
ComicBook / Amanda Kay Oaks06-17-2026
ShadowByt3$ demanded $2 million ransom from Nintendo after claiming a breach via TinyPulse, with Nintendo reporting employee data impact only.
Otakukart / Mohsin Nakade06-15-2026
SHADOWBYT3$ claimed an alleged Nintendo data breach via TINYpulse, demanding $2 million and threatening a leak if payment was not made.
Resetera06-16-2026
On June 13, 2026, threat actor SHADOWBYT3$ claimed an unverified Nintendo breach involving about 859 MB of TINYpulse employee data.
Otakukart / Mohsin Nakade06-17-2026
Nintendo said a suspected breach tied to TinyPulse did not compromise internal systems and did not expose customer data.
DigitalShield / Alberto Payo06-18-2026
ShadowByte$ claimed an 859 MB Nintendo corporate data breach with a $2 million ransom demand, while Nintendo attributed the incident to a TinyPulse provider weakness.
Resetera06-17-2026
ShadowBytes issued a June 12 ransom threat to leak 859MB of Nintendo employee data and later targeted TinyPulse after the ransom demand was not met.