ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Nintendo of America's employee data stolen by Shadowbyt3$ extortion group

Nintendo of America, a wholly-owned subsidiary of Japanese video game company Nintendo, said a third party data breach compromised information associated with its employees but did not impact its systems.

Linked InXFacebook
bookmark_borderSave to Library

Nintendo of America, a wholly-owned subsidiary of Japanese video game company Nintendo, said a third party data breach compromised information associated with its employees but did not impact its systems.

 

The company said in a statement shared with several news outlets that a recent data breach claimed by threat actors did not involve its systems or operations, and occurred after hackers breached TinyPulse, a third party service the company uses to conduct internal employee surveys.

 

The company’s statement followed claims by the Shadowbyt3$ extortion-as-a-service group that it had stolen close to 850 MB of information about Nintendo’s employees and that it had demanded Nintendo to pay a ransom of $2 million within 48 hours to stop the data from being leaked online.

 

The extortion group claimed that the stolen information contained Nintendo of America employees’ full names, email addresses, employee IDs, W-9 forms, bank statements, survey data, progress plans and employee reports.

 

The group later said that it did not hack into Nintendo of America’s systems but obtained the data of a small number of employees who used TinyPulse to participate in internal surveys.

 

The group also shared online a link where people could download information about Nintendo of America’s employees that that group had stolen by breaching WebMD Health Services-owned TinyPulse.

 

x.com/H4ckmanac/status/2067849157369336011

 

“We are aware of an issue involving TinyPulse, a third-party service used for internal employee surveys at Nintendo of America,” Nintendo said. “Nintendo’s systems have not been compromised, and no personal customer or financial data has been accessed.

 

“The data involved is limited to internal survey content comprising a small subset of our employees, and most of the information dates back several years.

 

“We appreciate our employees’ willingness to share their perspectives, take all feedback seriously, and take action when needed. We are working with the service provider to address the issue,” the company added.

 

The company did not state how many current and former employees were affected by the data breach and did not comment on the ransom demanded by the Shadowbyt3$ extortion group.  

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543