AUTO-UPDATED

Nintendo confirms data stolen via third-party cyberattack — but sadly no big secrets were revealed

Nintendo of America confirmed a third-party data breach involving the employee engagement platform TinyPulse, where hackers claimed to steal 1GB of internal data and demanded a $2 million ransom.

Key Points

  • The hacking group Shadowbyt3$ claims to have exfiltrated employee names, emails, and internal survey data dating from 2016 to 2026.
  • Nintendo of America stated that its own internal systems remain secure and no customer or financial information was accessed during the incident.
  • The company confirmed the breach was limited to the TinyPulse platform and involved a small subset of its workforce.
  • Shadowbyt3$ leaked alleged internal employee messages after Nintendo reportedly failed to meet the 48-hour deadline for ransom negotiations.

Why it Matters

This incident highlights the growing security risks companies face when sensitive employee data is stored on third-party software-as-a-service platforms. It serves as a reminder for organizations to rigorously vet the security protocols of all external vendors to prevent potential extortion attempts and data leaks.
TechRadar Published by Sead Fadilpašić
Read original