breach
Nintendo Employee Survey Data Stolen in TinyPulse Breach
2026-06-19

Nintendo of America has confirmed that survey data belonging to some of its employees has been stolen. Not from Nintendo, mind you. From TinyPulse, the third-party engagement platform it uses to gather internal feedback. Nintendo's own systems are untouched, no customer or financial data is involved, and the company stresses that most of the exposed material is several years old.
The extortion crew tells a less tidy version of events.
What the attackers claim
A newish outfit going by Shadowbyt3$ says it has roughly 1GB of data, including names, email addresses, bank statements, W-9 forms, employee IDs and internal messages dated between 2016 and 2026. They asked Nintendo for two million dollars, gave the company 48 hours, and when no payment landed, started leaking.
Nintendo's framing (old data, narrow scope) and the attackers' framing (recent, sensitive, financial) do not really agree. That tension is normal in these stories. The truth usually sits somewhere awkward in the middle, and the people who can confirm it are the ones least keen to talk.
The vendor in the middle
TinyPulse is owned by WebMD Health Services, which had not responded to questions at the time of the original reporting. Shadowbyt3$ has also dropped hints that other TinyPulse customers will be named, which would shift this from a Nintendo headline to something broader: a single SaaS vendor sitting quietly behind the HR processes of a long list of well-known employers.
That is the genuinely interesting part. Nintendo is the name in the headline because Nintendo sells the news. But the breach itself is not really about Nintendo. It is about a feedback tool most employees probably could not name, holding years of staff data on behalf of organisations that almost certainly assumed someone, somewhere, was looking after it.
If you're a gamer
Nothing to do. No accounts exposed, no payment details, no consumer data. Play your Switch in peace.
If you run a business
The pattern here is the one that keeps repeating. The sensitive information was not sitting inside the well-known brand. It was sitting inside the small SaaS tool the brand uses to run a slice of its HR work. Engagement surveys. Pulse checks. Wellness platforms. Benefits portals. Each of them holds more than it looks like it should, and most of them are signed off by someone who is not in security.
A few things worth doing this week:
- List the HR and people-ops SaaS tools your organisation actually uses. Not the ones in the official register. The ones being used.
- Find out what each one holds. Free-text survey responses can contain salary complaints, medical detail, accusations against colleagues, all sorts.
- Check who owns the vendor and where the data lives. TinyPulse is owned by WebMD. Plenty of small tools sit under parents you would not guess.
- Ask what the breach notification path looks like. If your vendor's vendor is compromised, when do you hear about it, and from whom?
None of this stops a determined attacker. It does mean that when the next Shadowbyt3$ shows up on a leak site with someone else's payroll data, you already know whether your name is on the list.