Nintendo Acknowledges Employee Data at Risk After Third-Party Service Breach

Nintendo has acknowledged that employee data was compromised following a breach of TinyPulse, a third-party service the company uses for internal employee surveys. The breach did not affect Nintendo’s own systems, which remain secure, according to the company’s statement.

A group calling itself ShadowByt3$ claimed responsibility for the breach, asserting that approximately 1 GB of data was stolen from the TinyPulse service. The allegedly exposed data includes employee names, email addresses, survey data, analytics reports, bank statement PDFs, and information about the company’s top-performing staff.

The threat actors have demanded a $2 million ransom, claiming they will leak the stolen data if Nintendo does not comply. The extortion attempt represents a typical “extortion as a service” operation, where threat actors demand payment to prevent the public release of compromised information.

Nintendo has assured users and customers that no personal customer data or financial information has been accessed, and that its core systems remain uncompromised. The breach is limited to the third-party employee survey service and does not affect the security of Nintendo’s gaming platforms or customer-facing services. This incident highlights the risks associated with third-party service integrations and the importance of supply chain security in the technology industry.

Sources