Nintendo got dragged into a $2 million ransomware story without actually being hacked.
Nintendo, one of the most renowned gaming brands in the world, reportedly had nearly 1 GB of employee data stolen in a breach tied to a $2…
Nintendo got dragged into a $2 million ransomware story without actually being hacked.

Nintendo, one of the most renowned gaming brands in the world, reportedly had nearly 1 GB of employee data stolen in a breach tied to a $2 million ransom demand. The leaked information allegedly included bank statements, W-9 forms, and private chats. What makes the incident particularly noteworthy is that Nintendo itself wasn’t directly hacked. Instead, the data was reportedly obtained through a third party, highlighting how supply-chain and partner vulnerabilities can put even the most iconic companies at risk.
What Actually Got in the Way of the World’s Most Iconic Gaming Company
On June 12 and 13, 2026, a hacker crew calling itself SHADOWBYT3$ bragged about stealing 859 MB of sensitive Nintendo employee data. They demanded $2 million to keep it off the web. But they didn’t crack Nintendo. Instead, they got in through TINYpulse — a third-party HR platform Nintendo used to run staff surveys.
Full names, emails, employee IDs, bank statement PDFs, tax forms, survey results, analytics, and personal workplace feedback collected over the last ten years. All of it.
SHADOWBYT3$ first gave Nintendo two days to respond. When Nintendo went silent, the hackers shifted their aim to TINYpulse, stretching the deadline to June 16, 2026.
Nintendo’s official statement was “Our own systems stayed safe.”, no customer or financial data was leaked. The breach only hit survey content from a small number of employees.
They’re right. Technically.
What’s Behind the Doors
If we’re being honest, this isn’t really about Nintendo. It’s about our endless stack of SaaS tools.
SHADOWBYT3$ didn’t bother going through Nintendo’s main systems. That would have been tough. Instead, they slipped in through a neglected HR survey tool buried deep in Nintendo’s vendor list, holding years of employee data that almost nobody thought to protect.
That’s a third-party supply chain attack. And right now, it’s the fastest-growing problem in cybersecurity.
A 2024 RSA Conference survey found that 87% of Fortune 1000 companies were hit with a significant cyber incident through a third-party provider — in just the last year alone.
Every SaaS product you plug in widens the gap. Sign up for a new benefits app, CRM, or survey tool, and suddenly your entire business depends on how careful someone else’s engineers are with your data.
It used to work like this: once a year, someone on your team fired off a security questionnaire to each vendor and ticked the “done” box. That approach is useless now.
Groups like SHADOWBYT3$ look for weak backstage doors, not obvious front gates. Extortion-as-a-Service means they scan for holes in your SaaS supply chain, not just your main perimeter. Why attack the entrance when there are forty unlocked windows around the side?
The truth is: most companies have zero real-time insight into what their SaaS tools are actually doing with their data. If you can’t see it, you won’t worry until you’re already in trouble.
What Companies Should Do Right Now
You don’t have to be a giant like Nintendo to get targeted. All it takes is one weak third party in your stack.
Here’s what security teams and SaaS leaders need to do right now:
1. Audit every third-party SaaS connection. List every tool that touches employee or customer data. You need a clear map to avoid leaving yourself exposed.
2. Quit the “once a year” vendor checkup routine. Compliance checkboxes don’t cut it anymore. Start monitoring your third-party vendors continuously. If something changes in their security posture, you should know immediately.
3. Push zero-trust past your own walls. Treat every outside partner as a potential risk. Only let vendors access the bare minimum data they actually need. Least-privilege policies aren’t just for internal teams.
4. Track what data each vendor stores and for how long. TINYpulse held Nintendo employee data for ten years. That’s ten years of accumulated risk. Set hard data retention rules in every vendor contract.
5. Build an incident response plan specifically for third-party breaches. When your vendor gets hit, your customers and the press will still come to you for answers. Don’t wait until you’re already scrambling.
The Takeaway
Nintendo’s gaming servers are just fine. Nobody’s coming for Mario.
But in some hacker’s toolbox right now, there’s a folder full of bank statements and private employee conversations belonging to real people. Those people are now bargaining chips.
Nintendo didn’t slip up on their own turf. The problem started when a seemingly harmless survey tool turned out to be the weak spot nobody bothered to check.
So which apps in your SaaS stack could open the door for someone else?
If you’re not sure, you just found your weak link.
메타데이터
- post_id
- b65a09e7b9a5
- slug
- nintendo-got-dragged-into-a-2-million-ransomware-story-without-actually-being-hacked-b65a09e7b9a5
- url
- https://medium.com/@insaas/nintendo-got-dragged-into-a-2-million-ransomware-story-without-actually-being-hacked-b65a09e7b9a5
- canonical_url
- https://medium.com/@insaas/nintendo-got-dragged-into-a-2-million-ransomware-story-without-actually-being-hacked-b65a09e7b9a5
- author_url
- https://medium.com/@insaas
- status
- ok
- fetched_at
- 2026-06-20 20:29:01