Threat actor ShadowByte$ claimed to have stolen about 859 MB of internal Nintendo data and demanded $2 million to keep it from being released, though Nintendo had not publicly confirmed the incident. Researchers who reviewed leaked samples said parts of the dataset appeared credible, citing employee survey records dating back to 2016, references to current staff, and file metadata reportedly showing creation dates of 2026-01-28.
The exposed material reportedly includes employee names, corporate email addresses, HR surveys, internal analytics, performance and progress-tracking data, exported reports, planning documents, and potentially sensitive financial records such as bank statement PDFs and W-9 forms. Reporting indicates the data may have been obtained through TinyPulse or another third-party HR or SaaS provider rather than through a direct compromise of Nintendo’s core systems, raising risks of phishing, identity theft, and fraud tied to third-party data handling.

See attribution, scope, and your downstream exposure.
4 events from the most recent confirmed update back to the earliest known activity.
Nintendo of America confirmed that data was stolen from TinyPulse, a third-party employee survey service owned by WebMD Health Services, while stating Nintendo’s own systems were not compromised. The company said the exposed data was limited to internal survey content affecting a small subset of employees, was mostly several years old, and did not include customer personal or financial data.
A threat actor using the name ShadowByte$ claimed to have stolen roughly 859 MB of internal Nintendo data spanning about a decade and demanded $2 million to prevent its public release. Reported samples included HR-related records, employee information, surveys, analytics, and planning documents, while Nintendo had not publicly confirmed the incident.
Threat intelligence reporting said SHADOWBYT3$ allegedly exfiltrated about 859 MB of Nintendo-related internal data, but the claim and dataset had not been verified as of June 13, 2026. Reporting also noted a possible link to third-party provider TINYpulse rather than a direct compromise of Nintendo infrastructure.
Researchers reviewing leaked samples said some file metadata showed creation dates of January 28, 2026, which they cited as one indicator that at least part of the dataset may be authentic.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
8 references tracked. Mallory keeps watching after this page renders.
teiss.co.uk
Open sourcexakep.ru
Open sourcehackread.com
Open sourcecysecurity.news
Open sourcescworld.com
Open sourcebleepingcomputer.com
Open sourcetechrepublic.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.