Gadgetreview
Shadowbyt3 Ransomware Group Claims Nintendo Employee Data Theft via TINYpulse
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On June 14, 2026, the ransomware group Shadowbyt3$ announced a breach involving TINYpulse, claiming to have exfiltrated 859 MB of sensitive employee data from Nintendo. The attack targeted TINYpulse, an HR platform, rather than Nintendo's gaming infrastructure, affecting 115 Nintendo employees and exposing personal information such as W9 forms and private messages. The attackers have set a ransom deadline of June 16, 2026, threatening to leak the data if their demands are not met. Security researchers have flagged the incident as 'pending verification,' indicating that the breach's authenticity is still under scrutiny. The incident highlights the risks associated with third-party SaaS providers as potential entry points for supply chain attacks. Organizations are advised to audit third-party integrations and monitor for unauthorized access attempts. No confirmed breaches of customer gaming accounts have been reported, and the incident primarily affects internal HR data.
Key Points: • Shadowbyt3$ claims to have stolen sensitive employee data from Nintendo via TINYpulse. • The breach reportedly affects 115 employees and includes personal information like W9 forms. • Organizations should audit third-party SaaS integrations to mitigate supply chain attack risks.