Just recently, a hacker group called “ShadowByt3$” claimed that they had successfully stolen 859MB of important investigative data files from Nintendo. Although it may not seem like much, the content is suspected to contain a large number of personal information such as names, email addresses, and bank statement information. They also used this to demand a ransom of up to $2 million from Nintendo. However, Nintendo officials also confirmed the incident in a subsequent response, but emphasized that no consumer personal information has been leaked.

As one of the most well-known large-scale game publishing companies in the world, Nintendo has indeed been directly attacked by hacker groups in the past, but according to official follow-up investigations and responses, the recent leak attack seems to have originated from a third-party partner.
🚨Cyber Alert ‼️🇯🇵Japan – 𝗡𝗶𝗻𝘁𝗲𝗻𝗱𝗼SHADOWBYT3$ claims to have breached Nintendo, allegedly stealing approximately 859 MB of data from TINYpulse systems. The claimed dataset includes employee names, email addresses, surveys, analytics reports, bank statement PDFs, W-9 forms, workplace feedback, etc.
According to the latest post published by the hacker intelligence agency “Hacmanac” on Bluesky, the hacker organization ShadowByt3$ is suspected to have recently successfully invaded the TinyPulse platform used by Nintendo of North America to conduct internal employee opinion surveys, and claimed to have obtained nearly 1GB of important data, including employee names and emails, survey content, financial forms, and reports from 2016 to 2026. Later, they even used this to require Nintendo to pay a ransom of US$2 million before June 15, otherwise the relevant information will be disclosed to the public.
In response to this, Nintendo said in a public response that they are currently working with TinyPulse to deal with this data leakage. They also emphasized that their internal systems have not been compromised. Therefore, this wave of personal information stolen by hackers seems to be limited to internal Nintendo employees in North America, not consumers.

In a follow-up note, Nintendo emphasized that the scope of the leaked TinyPulse data was very limited, and even only included investigation content from several years ago. Since Nintendo has quickly grasped the situation of this incident, it is almost impossible for them to choose to compromise with the ShadowByt3$ organization. Considering that Nintendo has always used strict legal means to protect its intellectual property rights, it is worth watching what measures they will take in the future to strengthen the security of employee and customer data.
But what is certain is that Nintendo has encountered larger-scale data leaks before. For example, the “Teraleak” incident that broke out in 2024 caused more than 1TB of data within Game Freak to be directly disclosed to the world, resulting in the complete leakage of the source code of multiple games and the public information of the “Pokémon” series. In the second wave of leaks that broke out again in 2025, news of the then-unreleased tenth-generation new game “Pokémon: Storm/Wave” leaked in advance.

In addition to Nintendo, many AAA game publishers are also frequently targeted by hackers. Another most talked about case in recent years is, of course, the massive leak of “Grand Theft Auto 6” that broke out in 2022. At that time, a member of the hacker group “Lapsus$” successfully invaded Rockstar Games’ internal Slack server and database through phishing methods, resulting in more than 90 pieces of “Grand Theft Auto 6” development footage being released to the Internet.
Source: KOCPC Chinese