Nintendo confirms data stolen in WebMD subsidiary cyberattack
Nintendo of America confirms that data from TinyPulse, a WebMD subsidiary used for internal employee surveys, was stolen in a cyberattack, but its systems and customer data were not compromised. Shadowbyt3$ claims to have stolen about 1GB of data and is demanding a $2 million ransom; Nintendo says the breach affected only internal survey data from a small group of employees dating back years and is cooperating with the service provider, with no action required by customers.

Nintendo Confirms Data Stolen in TinyPulse-Linked Cyberattack
OverviewNintendo of America has confirmed that a third-party survey service used for internal employee feedback was the target of a cyberattack. While Nintendo states that its own systems were not breached and customer data remains unaffected, the incident has drawn attention to the broader risk posed by vendors and the potential exposure of internal employee information.
What Happened
- The event centers on TinyPulse, a third-party platform used by Nintendo of America for anonymous employee surveys, engagement analytics, feedback collection, and workplace culture assessments.
- Nintendo’s official message emphasizes that its own IT environment was not compromised and that no personal customer or financial data was accessed.
- The breach specifically involved data hosted by TinyPulse, and Nintendo says the impact is limited to internal survey content from a subset of employees, with most information dating back several years.
What Data Was Involved
- The data described by Nintendo as affected includes internal survey content and related analytics. Nintendo characterizes this as a small subset of employees.
- Shadowbyt3$—the extortion-ware group claiming responsibility—has asserted that the stolen data could include more sensitive employee details, including personal information and direct messages. The group claimed the data dump could reach nearly 1GB and included names, email addresses, bank statements, W-9 forms with employee IDs, progress plans, and historical reports dating from 2016 through 2026.
- It is important to note that BleepingComputer did not verify or download the leaked data, and Nintendo has not confirmed the broader scope of personal data exposure beyond the company’s own statements.
Threat Actor and Ransom Demands
- Shadowbyt3$ identifies itself as an “extortion-as-a-service” group active since October 2025 and has threatened to leak data if a ransom is not paid.
- The initial message from the group demanded a ransom of 2 million dollars and threatened to leak the data within 48 hours unless negotiations were pursued.
- A subsequent post indicated that the breach did not affect Nintendo’s gaming systems but could affect a subset of Nintendo employees who used TinyPulse. The actor hinted at additional victims if a settlement was not reached.
Nintendo’s Response
- Nintendo states that its systems were not compromised and no customer or financial data was accessed.
- The data involved is described as limited to internal survey content and related analytics, affecting a small number of employees, with many items dating back years.
- Nintendo asserts ongoing collaboration with the TinyPulse service provider (WebMD Health Services’ TinyPulse platform) to address the issue and mitigate risk.
Impact on Customers and Employees
- Nintendo emphasizes that customer information remains unaffected and no actions are required by account holders.
- The security focus is on employees and internal data tied to survey responses, engagement metrics, and potentially some personal information associated with the TinyPulse accounts of a subset of Nintendo employees.
Official Communications and Verification
- Nintendo provided statements to BleepingComputer clarifying the scope and impact of the incident.
- Requests for additional details and clarification from WebMD Health Services, the owner of TinyPulse, did not receive a response by the time of reporting.
- Public records from the threat actor and media coverage describe conflicting claims about the breadth of exposed data; Nintendo’s and the security community’s interpretations rely on official company statements and independent verification.
Security and Risk Implications
- Vendors and third-party services introduce potential attack surfaces that can expose internal data even when the primary company’s systems are secure.
- The case highlights the importance of careful vendor risk management, data minimization for third-party platforms, and rigorous access controls for internal tools used for employee engagement and feedback.
- It also underscores the ongoing debate around ransom payments and law enforcement guidance regarding extortion-based cybercrime.
Related Context and Continuity
- Shadowbyt3$ positions itself as a relatively new actor in the extortion landscape, leveraging data leaks as leverage to extract payment from victim organizations.
- The broader security community continues to monitor extortion groups that threaten to expose internal communications and personal information unless a ransom is paid.
- Ongoing investigations and responses from affected entities may shape best practices for third-party risk assessments and breach disclosure moving forward.
Notes on the Incident Narrative
- The incident is framed by competing narratives: Nintendo’s official stance that core systems and customer data remain secure, and Shadowbyt3$ claims about the breadth of stolen information.
- The discrepancy between what the threat actor asserts and what has been independently verified underscores the need for cautious interpretation of leaked data claims and for continued official updates as investigations progress.
Contextual Takeaways for Organizations
- When relying on third-party platforms for internal processes (surveys, engagement metrics, feedback loops), consider integrating vendor risk reviews, data flow mappings, and regular security posture checks.
- Implement data segmentation and access controls to limit exposure of internal data in any external service.
- Establish clear incident response playbooks that address third-party service breaches, including communications with employees and stakeholders when internal data might be involved.
- Maintain a monitoring and verification plan for vendor-provided services, with a defined protocol for coordinating with the vendor and, if necessary, with law enforcement and regulatory bodies.
Timeline Highlights (Key Milestones Evident in Public Coverage)
- Date range of exposure: data claimed to span 2016–2026, with potential access to older and newer records depending on the scope of TinyPulse usage within the organization.
- Ransom window: 48 hours for initial negotiation, as stated by the threat actor, followed by ongoing claims about data exposure and potential additional victims if demands are not met.
- Current status: public statements from Nintendo affirm limited impact, while the security community continues to assess the veracity and extent of the alleged data exposure.
Final Observations
- The incident serves as a reminder of the friction points that arise when large entertainment organizations depend on external service providers for internal people processes.
- The evolving narrative around the breach—along with the actions or inactions of the involved parties—will influence how similar incidents are managed in the future and may drive changes in vendor risk management and data handling practices across the industry.


