Skip to content
Ransomware Group Shadowbyt3 Targets Tinypulse Exfiltrates Nintendo Employee Data

Ransomware Group Shadowbyt3 Targets Tinypulse Exfiltrates Nintendo Employee Data

qpulse.quasarcybertech.com June 15, 2026

Organizations must immediately audit third-party SaaS integrations and infostealer exposure to prevent supply chain data exfiltration.

On June 14, 2026, the threat actor group Shadowbyt3$ announced a breach involving TinyPulse and Nintendo. The group claims they did not breach Nintendo directly but targeted TinyPulse to exfiltrate PII, operational plans, and private employee chats. The attackers stated that the breach does not affect Nintendo's gaming operations but focuses on a small amount of employees who utilized the TinyPulse platform.

The incident reportedly impacts a subset of Nintendo employees. The attackers have provided a deadline of June 16, 2026, for TinyPulse to meet their ransom demands, threatening to leak the stolen data, which includes W9 forms containing employee IDs and private messages, if payment is not received. The group has published a file tree of the stolen data as proof of the breach.

According to data provided by HudsonRock, the incident involved 115 compromised employees, 1,237,367 compromised users, and 32 third-party employee credentials. The attackers explicitly stated that they are demanding that TinyPulse pays the ransom to prevent the leak of private messages and employee data.

This incident highlights the significant risk posed by third-party SaaS providers as an entry point for supply chain attacks. Even when a primary organization is not directly breached, the compromise of a vendor can lead to the exposure of sensitive internal communications and PII, such as W9 forms and employee IDs.

Defenders should prioritize auditing third-party vendor access and monitoring for infostealer infections, which HudsonRock identified as a contributing factor in this incident. Organizations should review their data sharing agreements with SaaS providers and ensure that sensitive employee data is not unnecessarily exposed or stored in third-party environments.

If you are an employee of a company that uses TinyPulse, be aware that your personal information, including W9 forms and private messages, may have been compromised. Monitor your accounts for suspicious activity and be vigilant against potential phishing attempts that may use this stolen information to appear legitimate.

Audit all third-party SaaS integrations for potential data exposure and credential leakage.

Monitor for unauthorized access attempts using credentials potentially compromised via infostealers.

Implement strict access controls and data minimization policies for third-party SaaS platforms.

Review third-party risk management policies and vendor security assessment procedures.

Advisory purposes only · QPulse Security Intelligence Platform · 2026 · Brief # 04053