Nintendo Data Breach Statement Follows TinyPulse Hack And $2 Million Demand

Black and red nintendo switch (Photo by Erik Mclean on Unsplash )

Black and red nintendo switch (Photo by Erik Mclean on Unsplash)

Summary
  • A ransomware group has demanded $2 million over TinyPulse data tied to Nintendo employees
  • SHADOWBYT3$ said it obtained 859MB of employee names, bank statements and analytics
  • Nintendo of America said its systems were not compromised and no customer data accessed
  • Company said affected data is internal survey content from a small subset of employees

Nintendo has acknowledged an issue involving TinyPulse, and its nintendo data breach statement says internal survey content from a small subset of employees was exposed, with most of the information dating back several years.

Reporting says a ransomware group behind the incident is seeking a $2 million payment to prevent release of the material, and the actor SHADOWBYT3$ said it obtained 859MB of Nintendo employee data through TinyPulse.

SHADOWBYT3$ described the seized material as including employee names, bank statements, employee IDs and reports, analytics and additional internal information, as reported by coverage of the event.

Company Response And Scope

Nintendo of America told Kotaku that Nintendo’s own systems were not compromised and that no personal customer or financial data has been accessed, according to the company statement quoted in reports.

The company said the data involved is limited to internal survey content comprising a small subset of employees, and that most of the information dates back several years, and it said it is working with the service provider to address the issue.

Reports indicate employees outside of North America were apparently not involved, and Nintendo emphasized it takes employee feedback seriously while pursuing remediation with the third party service.