惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Hugging Face - Blog
Hugging Face - Blog
量子位
H
Help Net Security
Microsoft Azure Blog
Microsoft Azure Blog
MongoDB | Blog
MongoDB | Blog
小众软件
小众软件
爱范儿
爱范儿
博客园 - 【当耐特】
Vercel News
Vercel News
S
SegmentFault 最新的问题
M
MIT News - Artificial intelligence
F
Fortinet All Blogs
Apple Machine Learning Research
Apple Machine Learning Research
GbyAI
GbyAI
博客园 - 叶小钗
博客园_首页
V
Visual Studio Blog
宝玉的分享
宝玉的分享
B
Blog
MyScale Blog
MyScale Blog
C
Check Point Blog
博客园 - 三生石上(FineUI控件)
L
LangChain Blog
V
V2EX

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing ...
Abinaya · 2026-06-16 · via Cyber Security News

Threat intelligence sources have reported that the threat actor group SHADOWBYT3$ has allegedly breached Nintendo, claiming to have exfiltrated approximately 859 MB of sensitive internal data.

The incident, first observed on June 13, 2026, remains unverified at the time of writing. However, early details suggest potential exposure of employee-related information.

The alleged breach is linked to TINYpulse systems, a platform commonly used by organizations for employee engagement, surveys, and internal feedback management.

If confirmed, this could indicate a third-party exposure vector rather than a direct compromise of Nintendo’s core infrastructure. The threat actor claims the dataset includes a wide range of sensitive information.

Breach of Nintendo

Reportedly, stolen data includes employee names, corporate email addresses, internal surveys, analytics reports, workplace feedback records, and employee progress-tracking data.

More concerningly, the dataset is said to contain financial documents such as bank statement PDFs and W-9 forms, which could significantly increase the risk of identity theft and financial fraud.

While the total size of the alleged leak, 859 MB, may appear moderate compared to large-scale breaches, the nature of the exposed data raises serious security and privacy concerns.

Documents like W-9 forms often contain personally identifiable information (PII), including tax identification numbers, making them highly valuable to cybercriminals for activities such as phishing, social engineering, and financial fraud campaigns.

According to a cyber alert shared by Hackmanac, SHADOWBYT3$ is believed to be a financially motivated threat actor. However, little public information is currently available regarding the group’s past activities or tactics.

The ESIX score for this incident is 5.60, indicating a moderate potential impact based on early assessments.

It is important to note that the breach claim is still pending verification. Nintendo has not yet issued an official statement confirming or denying the incident.

In similar cases, threat actors may exaggerate or misrepresent data to gain attention or increase pressure to pay a ransom.

🚨Cyber Alert ‼️

🇯🇵Japan – 𝗡𝗶𝗻𝘁𝗲𝗻𝗱𝗼

SHADOWBYT3$ claims to have breached Nintendo, allegedly stealing approximately 859 MB of data from TINYpulse systems. The claimed dataset includes employee names, email addresses, surveys, analytics reports, bank statement PDFs, W-9… pic.twitter.com/ElrsrKesjq

— Hackmanac (@H4ckmanac) June 13, 2026

Therefore, validation of the dataset and its origin remains critical before drawing definitive conclusions.

If verified, this incident would highlight ongoing risks associated with third-party platforms and employee management systems.

Attackers increasingly target such services as they often store aggregated sensitive data while potentially lacking the same level of security controls as primary enterprise systems.

Security experts recommend that organizations using platforms like TINYpulse review their access controls, enforce multi-factor authentication, and monitor for unusual data access patterns.

Additionally, employees should remain vigilant for phishing attempts that may leverage leaked personal or corporate information.

As the situation develops, further analysis is expected to determine the authenticity of the claims, the exact attack vector, and the potential impact on Nintendo and its workforce.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.