Kyoto, Japan & Redmond, Washington – June 16, 2026 – Nintendo of America (NOA) has issued a statement addressing claims of a data breach that allegedly compromised internal employee survey data. The company confirmed that a breach occurred, but emphasized that it was limited to "internal survey content comprising a small subset of our employees," and that "most of the information dates back several years." Crucially, NOA stated that their own systems were not compromised, and no personal customer or financial data has been accessed. The company is currently working with the third-party service provider, TinyPulse, to resolve the issue.
Initial Allegations Surface from Hacking Group
The situation began to unfold on June 13, 2026, when the hacking group known as ShadowByt3$ made public allegations of a significant data breach targeting Nintendo. According to reports initially surfaced by Technadu and subsequently amplified by Nintendo Everything, the group claimed to have exfiltrated approximately 859 megabytes (MB) of Nintendo employee data. ShadowByt3$ reportedly issued an ultimatum, demanding a response from Nintendo by June 15, 2026.
The data allegedly stolen was described as highly sensitive, including full names of employees, bank statements, employee identification numbers, internal reports, and analytics. This information, if confirmed, would represent a serious breach of employee privacy and potentially expose individuals to identity theft and other forms of malicious activity.
The Role of TinyPulse: A Common Vector for Attack
Investigations into the alleged breach quickly pointed towards TinyPulse, a third-party service used by Nintendo of America for its internal employee engagement and feedback initiatives. TinyPulse, a platform designed to enhance company culture and performance through employee surveys and feedback, is part of WebMD Health Services.

The tactic of targeting a third-party vendor that serves a larger organization is a well-established modus operandi for many cybercriminal groups, particularly those engaged in ransomware attacks. By compromising a less secure third-party service, attackers can gain indirect access to the data of multiple larger clients. This approach often bypasses direct attacks on the primary organization’s more robust security infrastructure. The size of the alleged data dump, while smaller than some historical breaches, is significant due to the personal and internal nature of the information.
Chronology of Events: From Allegation to Official Response
The unfolding of this incident can be traced through a series of key dates:
- June 13, 2026: The hacking group ShadowByt3$ publicly claims to have breached Nintendo’s systems and stolen approximately 859MB of employee data. The group reportedly sets a deadline for Nintendo to respond.
- June 15, 2026: The deadline set by ShadowByt3$ passes. While details of any direct communication between the group and Nintendo during this period are not publicly available, the lack of an immediate public response from Nintendo suggests internal investigations were underway.
- June 16, 2026 (Evening Update): Nintendo of America issues an official statement confirming a data incident involving TinyPulse. The company clarifies the scope and nature of the compromised data, assuring that customer and financial information remains secure and that Nintendo’s own systems were not directly breached.
Supporting Data and Scope of the Breach
The initial claims from ShadowByt3$ painted a grim picture, detailing a substantial amount of sensitive employee information. The alleged exfiltration of:
- Full Employee Names: This data point alone can be used for targeted phishing attacks or social engineering.
- Bank Statements: The inclusion of financial documents is particularly concerning, as it could lead to direct financial fraud and identity theft.
- Employee IDs and Reports: Internal identification numbers and official reports can provide attackers with a deeper understanding of an organization’s structure and potentially reveal vulnerabilities.
- Analytics: Internal performance and operational analytics could offer insights into business strategies or employee performance, which could be leveraged for further attacks or corporate espionage.
While Nintendo has downplayed the overall impact, stating the data is "limited to internal survey content comprising a small subset of our employees" and that "most of the information dates back several years," the nature of the alleged data is still a cause for concern. Even older internal survey data, if it contains identifiable employee information, can be valuable to malicious actors.

This alleged breach, while smaller in scale than historical incidents like the "teraleak" affecting The Pokémon Company in 2024 or the earlier "gigaleak" involving Nintendo itself, carries significant weight due to the personal nature of the compromised data. The "teraleak" involved the theft of source code and internal documents related to Pokémon games, while the "gigaleak" exposed a vast trove of internal Nintendo documents, including prototypes and source code from various consoles and games. The current incident appears to be more focused on individual employee data.
Official Response from Nintendo of America
Nintendo of America’s official statement provided a crucial update and a degree of reassurance for both employees and the public. The statement, released on June 16, 2026, read:
"We are aware of an issue involving TinyPulse, a third-party service used for internal employee surveys at Nintendo of America. Nintendo’s systems have not been compromised, and no personal customer or financial data has been accessed. The data involved is limited to internal survey content comprising a small subset of our employees, and most of the information dates back several years. We appreciate our employees’ willingness to share their perspectives, take all feedback seriously, and take action when needed. We are working with the service provider to address the issue."
This statement addresses several key points:

- Acknowledgement of the Issue: Nintendo confirms an "issue" involving TinyPulse, validating the initial reports of a breach.
- Scope Limitation: The company explicitly states that Nintendo’s own systems were not compromised, a critical distinction that suggests the breach originated at the vendor level.
- Data Type Confirmation: The breach is characterized as containing "internal survey content" and affecting a "small subset of our employees," with the majority of the data being older. This helps to frame the severity and potential impact.
- No Customer Data Compromised: A significant reassurance is given that "no personal customer or financial data has been accessed," aiming to prevent wider panic among Nintendo’s vast customer base.
- Action and Collaboration: The commitment to working with TinyPulse signals a proactive approach to resolving the situation and preventing future recurrences.
The statement also includes a brief mention of valuing employee feedback, a subtle nod to the purpose of the compromised survey data.
Implications and Future Considerations
The alleged data breach, even with Nintendo’s assurances, raises several important implications:
- Third-Party Risk Management: This incident underscores the critical need for robust third-party risk management. Organizations must ensure that their vendors have stringent security protocols in place and that contracts include clear provisions for data protection and breach notification.
- Employee Privacy: Despite the limited scope, any breach of employee data is a serious matter. Nintendo will likely face scrutiny regarding its vetting processes for third-party services and its internal data security policies.
- Reputational Impact: While Nintendo has moved quickly to address the situation, any confirmed data breach can have a negative impact on public trust and employee morale. The sensitive nature of the stolen data, even if older, could still lead to reputational damage if not handled transparently and effectively.
- Legal and Regulatory Scrutiny: Depending on the jurisdiction and the specifics of the data compromised, Nintendo and TinyPulse could face legal and regulatory scrutiny. Data protection laws, such as GDPR or CCPA, often mandate strict reporting requirements and penalties for non-compliance.
- Ongoing Investigation: The statement "We are working with the service provider to address the issue" implies that the investigation is ongoing. The full extent of the breach and its root cause will likely be determined through this collaborative effort.
As Nintendo continues to work with TinyPulse to resolve this incident, the gaming community and cybersecurity professionals will be closely monitoring developments. The focus remains on ensuring the protection of employee data and reinforcing the security posture of all systems, both internal and those managed by third-party vendors. The company’s swift response and transparent communication are crucial steps in mitigating the potential fallout from this concerning event.







