ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Threat actor demands $2 million from Nintendo, claims theft of decade of corporate data

A threat actor has demanded $2 million from Nintendo Co., the Japanese video game giant, after claiming to have stolen a trove of internal corporate data stretching back to 2016, according to a post reviewed on a well-known cybercrime forum.


The actor, operating under the name ShadowByte$, alleges it obtained approximately 859 megabytes of data tied to Nintendo and has threatened to release the material if the ransom goes unpaid. The authenticity and full scope of the breach remain unverified, and Nintendo has not publicly commented on the claim.


Data samples published alongside the forum post appear to contain a range of internal corporate records, including employee names, corporate email addresses, internal analytics and reporting data, employee surveys and engagement feedback, organizational performance metrics, and internal planning documentation. Researchers who reviewed the samples found material consistent with human resources functions, including workplace feedback submissions and internal pulse survey data. "The sample contains HR data, such as pulse surveys and questionnaires about how employees are feeling at work," the researchers said.


The threat actor claims the records cover the period from 2016 through 2026, and researchers confirmed that portions of the material appear to date to 2016. Metadata associated with the exported files shows a creation date of January 28, 2026. If accurate, the dataset may represent close to a decade of historical employee feedback and internal reporting. Researchers were also able to identify individuals referenced in some of the survey data who appear to still be employed by Nintendo. "Some people from those pulse surveys are still at Nintendo and were identifiable, so the leak could be legitimate," one researcher noted.


The actor references TinyPulse, an employee engagement platform organizations use to collect anonymous workforce feedback and measure employee satisfaction. Researchers said the sample alone is not sufficient to determine whether attackers compromised Nintendo directly or accessed a third-party platform such as TinyPulse.


ShadowByte$ is believed to have begun operating around February 2026. The group previously claimed to have taken data from Starbucks Corp.’s Amazon Web Services cloud storage and demanded $500,000 from the company, though researchers said they found no indicators in the available data samples linking that material to Starbucks.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543