Ransomware victim disclosure
← All victimsNintendo Company (Nintendo.com)
Claimed by Shadowbyt3$ · listed 22 hours ago
Status timeline
- ListedJun 12, 2026
- Data leakeddate unknown
At a glance
- Group
- Shadowbyt3$
- Status
- Data leaked
- Country
- Japan
- Sector
- Technology
- Listed on leak site
- Jun 12, 2026
About the victim
AI dossier — public-source company profileNintendo Company is a Japanese multinational video game and entertainment corporation headquartered in Kyoto, Japan. The company is one of the world's largest and most recognized video game manufacturers, known for iconic franchises including Super Mario, The Legend of Zelda, and Pokémon.
- Industry
- Video Games & Entertainment
- Founded
- 1889
Attack summary
Severity: critical — Confirmed exfiltration of regulated PII at scale (employee full names, emails, financial records, W9 forms with IDs) combined with sensitive internal business data and communications. W9 forms and bank statements are particularly sensitive financial/tax records. Attack affects major public company with significant employee base.shadowbyt3$ claims to have exfiltrated approximately 859 MB of data from Nintendo's TINYpulse employee engagement platform. The group claims to have stolen employee personal information, financial records, bank statements, W9 forms, analytics, surveys, and internal communications, demanding $2 million ransom.
Data the group says was taken
AI dossier — extracted from the leak post- Employee full names and emails
- Bank statements and payment records
- W9 tax forms with employee IDs
- Employee engagement analytics and surveys
- Internal communications and personal conversations
- Performance reviews and progress plans
- Top employee rankings and dashboards
- Historical reports (2016-2026)
What the group claims
proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extortion as a service group. We stole close enough to 1gb. You have 48 hours to contact us nintendo or all data gets leaked. If you contact us we give you an extra day to think this through. We are demanding a ransom payment of 2 million dollars. Check your inbox if you work for nintendo and use TINYpulse or go login to tinypulse if the url in the leak looks familiar. You have 48 hours from this announcement then it gets leaked. You have till June 15 2026. size: 859.0MB Close enough to 1GB it contains the following: -full name first name, last name, email of employees -analytics - surveys - all reports exported - all bank statements of payment pdf and w9 forms with employee ids - all cheers exported - all wins dashboard and wall of wins exported - all progress plans exported - Reports from 2016 to up to date 2026 - Analytics of Employees contain conversations and personal feelings about work and more - Content library of personal questions and engagement analytics - TINYpulse and Nintendo top employees of Nintendo based on engagement
Sources
- Victim siteNintendo.com
Source
Indexed 22 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

