Skip to main content
Back to overview
Medium

Nintendo Employee Data Exposed via TinyPulse Third-Party Breach, Shadowbyt3$ Shifts Ransom Demand

Nintendo of America confirmed that internal employee survey data was stolen in a cyberattack targeting TinyPulse, a third-party employee engagement platform owned by WebMD Health Services.

Key points

  • Third-party breach affecting TinyPulse, a vendor to Nintendo.
  • Nintendo employee survey data stolen.
  • Shadowbyt3$ extortion group claimed responsibility.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Internal actor · Confidentiality impact

Possible insider activity

03

Potential impact

Data Exposure

Confidentiality

Published
Jun 14, 2026
Updated
Jun 29, 2026
Confidence
Medium
Evidence
3 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Possible insider activity

Watch exposure paths that could affect data, operations or third-party trust.

  • Source type: possible insider or internal misuse

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

TinypulseData DisclosureShadowbyt3Shifts Ransom Demand Nintendo ofAmericaTinyPulseWebMD Health Services. NintendoNintendoPDFsW-9

Quick context

Questions about this signal

What happened in this signal?

Nintendo of America confirmed that internal employee survey data was stolen in a cyberattack targeting TinyPulse, a third-party employee engagement platform owned by WebMD Health Services. Nintendo's own systems were not compromised, and no customer or financial data was accessed. The breach was claimed by the Shadowbyt3$ extortion group, which initially demanded a $2 million ransom from Nintendo on June 12, 2026, but shifted its demand directly to TinyPulse on June 14, 2026, after Nintendo declined to engage. The claimed dataset includes employee names, email addresses, analytics, survey records, bank statement PDFs, and W-9 tax forms.

When was this signal reported?

Shadow Tier lists Jun 14, 2026 as the signal date.

Which organization is connected to this signal?

Tinypulse is the organization connected to this public signal.

Explore Tinypulse
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence
Which sector context is relevant?

This signal is connected to healthcare cyber intelligence.

Explore healthcare cyber intelligence