Nintendo of America
ShadowByt3$ demands $2 million after stealing a decade of employee data through TinyPulse, Nintendo's HR survey vendor. Nintendo refuses. The data leaks.
What happened?
ShadowByt3$, an extortion-as-a-service group active since October 2025, published claims on June 12, 2026, that they had breached Nintendo of America through TinyPulse, a third-party HR survey platform owned by WebMD Health Services. They gave Nintendo 48 hours to respond.
When Nintendo declined to engage, ShadowByt3$ shifted their demands to TinyPulse on June 14. When both deadlines passed without payment, they began leaking data samples. Nintendo confirmed the breach on June 19, stating their own systems were not compromised—the attack vector was the SaaS vendor's cloud environment.
What data was actually inside?
Approximately 1GB of employee data spanning 2016 to 2026. Employee names, email addresses, and survey responses. But also: bank statements, W-9 forms with employee IDs, and progress plans. This isn't just sentiment data—it's financial and employment records accumulated over a decade.
TinyPulse is an employee feedback platform. It's supposed to collect engagement surveys and workforce analytics. The presence of W-9 forms and bank statements suggests either scope creep in what data was shared with the vendor, or the vendor's platform was connected to broader HR systems than intended.
Who gets hurt and how?
Nintendo of America employees—current and former—whose financial records are now exposed. W-9 forms contain Social Security numbers. Bank statements reveal financial institutions and account patterns. Combined with names and email addresses, this is a complete package for identity theft and financial fraud.
Ten years of employment records also means employees who left Nintendo years ago are affected. The HR vendor retained data long after the employment relationship ended. Someone who worked at Nintendo in 2016 may not expect their financial information to surface in a 2026 breach.
What did they think they were doing right?
Nintendo's statement emphasized that "Nintendo's systems have not been compromised, and no personal customer or financial data has been accessed." The perimeter held. Internal networks remained secure. The attack came through a third-party service.
Third-party risk management is the challenge here. Nintendo likely vetted TinyPulse when they engaged them. There was probably a security questionnaire, maybe a SOC 2 review. But vendor assessments are point-in-time snapshots. TinyPulse is owned by WebMD Health Services—a subsidiary of a subsidiary, with its own security posture that Nintendo doesn't control.
What did they not know about their own data?
Nintendo called the exposed data "limited" and "old." ShadowByt3$ says it spans ten years and includes financial records. These statements suggest Nintendo may not have fully inventoried what data they shared with TinyPulse—or what TinyPulse retained beyond its intended purpose.
Employee survey platforms shouldn't need W-9 forms or bank statements. Either that data was shared unnecessarily, or it was connected to broader systems through integrations. The gap between "internal employee surveys" and "W-9 forms" represents a failure to understand what sensitive data actually flowed to the vendor.
If a single credential in your environment was compromised today, could you say within 24 hours exactly what data was accessed?
What does attribution look like the morning after?
Employee data triggers notification obligations. W-9 forms contain SSNs—this is a clear notification trigger in every state. Nintendo must identify every employee whose data was shared with TinyPulse over the past decade and determine whose records were actually accessed.
The challenge with third-party breaches: Nintendo doesn't control the forensic investigation. TinyPulse must determine what was taken. Nintendo depends on their vendor's incident response capabilities to understand the scope of their own employee exposure. That dependency extends the timeline and reduces control.
What would have changed the outcome?
Inventorying what sensitive employee data actually flowed to third-party vendors—and enforcing data minimization on those integrations.
Supply chain security isn't just about vendor assessments. It's about knowing exactly what data you share with each vendor and whether that data exceeds what's necessary for the service. An employee survey platform doesn't need W-9 forms. The organizations that minimize their vendor data footprint minimize their breach exposure.
Nintendo found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.