惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
G
Google Developers Blog
aimingoo的专栏
aimingoo的专栏
罗磊的独立博客
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
D
Docker
博客园 - 三生石上(FineUI控件)
博客园 - 司徒正美
人人都是产品经理
人人都是产品经理
博客园 - 叶小钗
月光博客
月光博客
S
SegmentFault 最新的问题
Jina AI
Jina AI
Blog — PlanetScale
Blog — PlanetScale
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - Franky
L
LangChain Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Microsoft Azure Blog
Microsoft Azure Blog
阮一峰的网络日志
阮一峰的网络日志
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Last Week in AI
Last Week in AI

Hackread – Cybersecurity News, Data Breaches, AI and More

Operation Endgame Disrupts StealC, Amadey and SocGholish Malware Networks New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords Best Crypto Payment Solutions for E-Commerce Businesses Internet Society Foundation Opens Global Call for Common Good Cyber Fund to Strengthen Cybersecurity LastPass Confirms Customer Data Breach After Klue OAuth Token Theft ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking The Rise of AI-Powered Academic Fraud: Beyond Traditional Plagiarism New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto The Evolution of iGaming Fraud: What Security Teams Should Expect in 2027 2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users Texas Parks and Wildlife Data Breach Affects Over 3M License Customers Threat Hunting Beyond Alerts: Finding the Activity Detection Misses Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data MDR Provider Comparison: Time to Discover and Respond to Threats Meteor 3.0 Migration Helped Rocket.Chat Move Off End-of-Life Node.js Runtime Gcore Helps Ucom Safeguard Public Live Broadcast Infrastructure During Armenia’s Parliamentary Elections eFAQ Publishes Investigation Into Alleged Scam Activity and Coordinated Reputation Attacks FIFA World Cup 2026: Hackers Target Football Fans With Fake Tickets Sites MacBook Neo vs Windows Laptops for Cybersecurity Tasks Operation Endgame Disrupts SocGholish Malware Infrastructure What Businesses Should Know Before Migrating Their CMS DragonForce Ransomware Abused Microsoft Teams to Hide Malware Activity Agentjacking: Researchers Show How One Fake Bug Report Can Hijack AI Coding Agents FortiBleed Attack Exposes Fortinet Firewall Credentials in 194 Countries SpyCloud Report Finds Phishing Attacks Surge as Employee Data Is Exposed at 86% of Fortune 100 Companies 152 Chrome Live Wallpaper Extensions Hid Ad Tracking and Fake Search Clicks Heimdal Survey: Executives Four Times More Confident About AI Risk Than the Teams Managing It
Nintendo America Employee Data Exposed After Shadowbyt3$ ...
Deeba Ahmed · 2026-06-19 · via Hackread – Cybersecurity News, Data Breaches, AI and More

A third-party human resources platform called TinyPulse has become the victim of a supply-chain attack that resulted in the exfiltration of records belonging to Nintendo of America employees. The breach was confirmed by Nintendo following claims from the notorious Shadowbyt3 extortion group.

The attackers, reportedly, didn’t compromise Nintendo’s own network perimeter, but accessed the cloud environment of TinyPulse. For your information, this is an employee survey, feedback, and workforce analytics platform owned by WebMD Health Services. Since TinyPulse aggregates workforce metrics and personnel details of its client base, the infrastructure contained a large volume of identifiable employee data.

Cyberattack on Nintendo Vendor TinyPulse Allegedly Exposes Decade of Employee Records
Alert from VenariX Cyber Feeds on Telegram after SHADOWBYT3$ claims

Breach Details and Attribution

Shadowbyt3$, which emerged in October 2025 and operates as an extortion-as-a-service group, published this claim in the attack on 12 June 2026, and demanded a ransom payment of 2 million USD from Nintendo to prevent public data exposure. The group gave a 48-hour deadline to Nintendo for ransom payment, but the gaming giant declined to negotiate with them.

Following Nintendo’s refusal, Shadowbyt3$ shifted its financial demands directly to TinyPulse, setting a secondary deadline of 16 June. When this deadline passed without payment, they started leaking data samples onto their dark web platform.

Shadowbyt3$ claims to have stolen an 859-megabyte dataset comprising records from 2016 to early 2026, whereas according to Nintendo’s official statement, the exposed data is limited to a small subset of internal employee survey responses from previous years. Hackers still allege the files contain:

  • Bank statement PDFs
  • Employee names and corporate email addresses
  • W-9 tax forms containing employee identification numbers
  • Private messages and internal chat logs between staff members
  • Workforce progress plans and human resources analytics reports

Security experts have reviewed the published sample files and verified that multiple named individuals are active Nintendo of America employees.

Cyberattack on Nintendo Vendor TinyPulse Allegedly Exposes Decade of Employee Records
Screenshot from SHADOWBYT3$’s dark web leak site

Ongoing Security Risks for Corporate Personnel

The exposure of W-9 tax documents and financial records introduces long-term identity theft risks because hackers routinely use this information to file fraudulent tax returns and divert financial refunds. Along with that, the exfiltrated banking details can help scammers to create targeted phishing emails using accurate corporate details to manipulate victims.

However, since TinyPulse operates a multi-tenant software architecture serving hundreds of corporate clients, other businesses using the platform may face similar data exposure risks.

Nintendo confirmed that the scope of the incident is restricted to Nintendo of America personnel. It is still recommended that any employee who uses the TinyPulse platform must implement credit freezes with reliable credit bureaus like Equifax, Experian, and TransUnion. They must also carefully monitor their tax filings for unauthorized changes.