Gadgetreview Shadowbyt3 Ransomware Group Claims Nintendo Employee Data Theft via TINYpulse
Article Content
- •Shadowbyt3$ claims to have stolen sensitive employee data from Nintendo via TINYpulse.
- •The breach reportedly affects 115 employees and includes personal information like W9 forms.
- •Organizations should audit third-party SaaS integrations to mitigate supply chain attack risks.
On June 14, 2026, the ransomware group Shadowbyt3$ announced a breach involving TINYpulse, claiming to have exfiltrated 859 MB of sensitive employee data from Nintendo. The attack targeted TINYpulse, an HR platform, rather than Nintendo's gaming infrastructure, affecting 115 Nintendo employees and exposing personal information such as W9 forms and private messages. The attackers have set a ransom deadline of June 16, 2026, threatening to leak the data if their demands are not met. Security researchers have flagged the incident as 'pending verification,' indicating that the breach's authenticity is still under scrutiny. The incident highlights the risks associated with third-party SaaS providers as potential entry points for supply chain attacks. Organizations are advised to audit third-party integrations and monitor for unauthorized access attempts. No confirmed breaches of customer gaming accounts have been reported, and the incident primarily affects internal HR data.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (21)
Following this threat?
Track Nintendo in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…