Nintendo Confirms Employee Survey Data Exposed in TinyPulse Cyberattack
Nintendo of America has acknowledged that employee survey data was compromised in a recent cyberattack targeting TinyPulse, a third-party platform used for internal feedback. The company stated that its own systems remained secure, with no customer or financial information accessed.
The breach, disclosed following claims by the threat actor Shadowbyt3$, involved internal survey content tied to a small group of employees, most of which dated back several years. Nintendo emphasized that the incident was isolated to TinyPulse’s systems, not its internal infrastructure.
However, Shadowbyt3$ alleged the breach was more extensive, claiming to have exfiltrated nearly 1GB of data, including full names, email addresses, bank statements, W-9 forms, and employee progress reports spanning 2016 to 2026. The group demanded a $2 million ransom, threatening to leak the data if unpaid. After Nintendo reportedly refused, Shadowbyt3$ released samples of direct messages and employee conversations, suggesting broader exposure.
Nintendo continues to assert that the attack was limited in scope, while the threat actor maintains that sensitive employee data was stolen. The company is working with TinyPulse to address the incident. No further details have been provided at this time.
Source: https://thecyberexpress.com/tinypulse-cyberattack-nintendo/
HCSS cybersecurity rating report: https://www.rankiteo.com/company/hcss
Nintendo cybersecurity rating report: https://www.rankiteo.com/company/nintendo
"id": "HCSNIN1781857523",
"linkid": "hcss, nintendo",
"type": "Breach",
"date": "1/2016",
"severity": "60",
"impact": "3",
"explanation": "Attack with significant impact with internal employee data leaks"
{'affected_entities': [{'customers_affected': '0 (no customer data '
'compromised)',
'industry': 'Video Games',
'location': 'United States',
'name': 'Nintendo of America',
'type': 'Corporation'}],
'attack_vector': 'Third-party compromise (TinyPulse)',
'customer_advisories': 'Nintendo stated no customer or financial information '
'was accessed.',
'data_breach': {'data_exfiltration': 'Yes (claimed by threat actor)',
'file_types_exposed': ['Documents (W-9, bank statements)',
'Messages (direct conversations)'],
'personally_identifiable_information': 'Yes (full names, '
'email addresses, '
'financial documents)',
'sensitivity_of_data': 'High (PII, financial documents, '
'internal communications)',
'type_of_data_compromised': ['Employee survey data',
'Full names',
'Email addresses',
'Bank statements',
'W-9 forms',
'Employee progress reports',
'Direct messages',
'Employee conversations']},
'description': 'Nintendo of America confirmed that employee survey data was '
'compromised in a cyberattack targeting TinyPulse, a '
'third-party platform used for internal feedback. The breach '
'involved internal survey content tied to a small group of '
'employees, with most data dating back several years. The '
'threat actor Shadowbyt3$ claimed to have exfiltrated nearly '
'1GB of data, including sensitive employee information, and '
'demanded a $2 million ransom.',
'impact': {'brand_reputation_impact': 'Potential reputational damage due to '
'employee data exposure',
'data_compromised': 'Employee survey data, full names, email '
'addresses, bank statements, W-9 forms, '
'employee progress reports, direct messages, '
'and employee conversations',
'identity_theft_risk': 'High (due to exposure of PII and financial '
'documents)',
'payment_information_risk': 'High (bank statements and W-9 forms '
'exposed)',
'systems_affected': 'TinyPulse (third-party platform)'},
'investigation_status': 'Ongoing',
'motivation': 'Extortion (Ransom)',
'ransomware': {'data_exfiltration': 'Yes',
'ransom_demanded': '$2,000,000',
'ransom_paid': 'No (reportedly refused)'},
'references': [{'source': 'Nintendo of America Statement'},
{'source': 'Shadowbyt3$ Claims'}],
'response': {'communication_strategy': 'Public acknowledgment of the breach, '
'emphasizing limited scope',
'third_party_assistance': 'Working with TinyPulse to address the '
'incident'},
'threat_actor': 'Shadowbyt3$',
'title': 'Nintendo Employee Survey Data Exposed in TinyPulse Cyberattack',
'type': 'Data Breach'}