Nintendo experienced a data breach involving employee information through the third-party service TinyPulse, which handles employee surveys and feedback [1, 2]. The company confirmed its own servers were not compromised and no customer or financial data was accessed [1].
The data at risk includes employee names, emails, bank statements, survey feedback, analytics reports, internal survey content, and private conversations of some Nintendo employees [1, 2]. Nintendo said the affected data mainly concerns a small subset of employees and mostly dates back several years [1]. A spokesperson stated, "Nintendo's systems have not been compromised, and no personal customer or financial data has been accessed. The data involved is limited to internal survey content comprising a small subset of our employees, and most of the information dates back several years." [1]
The extortion group ShadowByt3$, which calls itself an "extortion as a service group," demanded a ransom payment of 2 million dollars to avoid leaking the data [1, 2]. On June 12, 2026, ShadowByt3$ publicly threatened to release 859 MB of employee data in a ransom demand directed at Nintendo [2]. They said, "You have 48 hours to contact us Nintendo or all data gets leaked. If you contact us we give you an extra day to think this through. We are demanding a ransom payment of 2 million dollars." [2]
After Nintendo refused to pay, ShadowByt3$ shifted their threats to TinyPulse, giving them a deadline of June 16 to respond or face data leaks including private messages of Nintendo employees [2]. ShadowByt3$ warned, "Tinypulse you have till june 16th 2026 to contact us via telegram or email that we have sent you. Nintendo decided to not pay so we are demanding that Tinypulse pay or all data will be leaked including private messages of Nintendo employees and not all employees are happy we can tell you that." [2]
Among the leaked information is data related to Nintendo of America's December 2025 decision to implement Copilot AI in the workplace despite employee opposition [2].
Nintendo is working with TinyPulse to respond to the breach and appreciates the feedback received from employees [1]. The company acknowledged the incident in June 2026, confirming the breach involved TinyPulse employee survey data and reiterating no customer data was compromised [1].