[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f30gyRdhQ0UxWaBjq1eFDGRM3oN-Uu5WCvk_3jbFlua8":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"company":11,"breachDate":15,"addedDate":16,"modifiedDate":16,"pwnCount":17,"totalRecords":17,"dataClasses":18,"description":20,"source":21,"isVerified":4,"isSpamList":22,"isSensitive":4,"severity":23,"processingStatus":24,"logoUrl":25,"contentUpdatedAt":16,"hasEnglishDescription":4},"6a66a2f956e8c0171a0fa22f","NintendoOfAmericaTinyPulse2026","Nintendo of America TinyPulse 2026 Data Breach","nintendo-of-america-tinypulse-2026","nintendo.com",{"name":12,"sector":13,"country":14,"website":10},"Nintendo of America Inc.","Gaming","United States","2026-06-17T00:00:00.000Z","2026-07-27T00:14:49.706Z",0,[19],"Internal employee survey content","\u003Cp>\u003Cstrong>The Nintendo of America TinyPulse 2026 data breach\u003C\u002Fstrong> is an incident in which the company confirmed that data was stolen from the third-party TinyPulse service used for internal employee surveys. Nintendo said its own systems were not compromised and that the verified scope was limited to internal survey content involving a small subset of employees, with most of the information dating back several years.\u003C\u002Fp>\n\u003Cp>BleepingComputer and Mashable published Nintendo of America's direct statement. Both report that no personal customer or financial data was accessed and that the incident was limited to the TinyPulse environment. Because the company did not disclose an exact employee count, file volume, attack date, or specific survey fields, LeakData keeps the person total at zero to mean unknown.\u003C\u002Fp>\n\u003Ch2>Confirmed Incident Scope\u003C\u002Fh2>\n\u003Cp>Nintendo of America acknowledged a security issue involving TinyPulse, a service used for employee-experience and feedback surveys. The company said data in the third-party environment was stolen and that it was working with the provider to address the issue. This confirmation makes the event a real data-access incident rather than a listing based only on an attacker's claim.\u003C\u002Fp>\n\u003Cp>The verified information type is internal survey content. Nintendo said it concerned a small subset of employees and that most of the content was several years old. Because the company did not publish a field-level inventory of questions, answers, comments, or metadata, this record uses one deliberately broad data class.\u003C\u002Fp>\n\u003Ch2>TinyPulse and the Third-Party Boundary\u003C\u002Fh2>\n\u003Cp>TinyPulse is a platform for employee engagement, anonymous feedback, surveys, and workplace-culture assessment and is part of WebMD Health Services. Nintendo explicitly said the event originated in this external service rather than its corporate or gaming infrastructure. The record should therefore not be interpreted as a Nintendo customer-account breach.\u003C\u002Fp>\n\u003Cp>The third-party boundary matters for responsibility and technical scope. Nintendo data was present in the provider's environment, but it created a distinct impact involving Nintendo of America employees. WebMD Health Services had not provided a detailed technical statement when the reports were published, leaving the entry method and impact on any other TinyPulse customers unknown.\u003C\u002Fp>\n\u003Ch2>What Data Was Confirmed?\u003C\u002Fh2>\n\u003Cp>The only data type confirmed by the company is internal employee survey content. That phrase may encompass feedback text, survey responses, or survey context, but Nintendo did not release a field-level inventory. LeakData does not treat names, emails, bank statements, tax forms, employee identifiers, or reports as verified categories.\u003C\u002Fp>\n\u003Cp>The phrase small subset of employees supplies no numerical total. Nintendo's overall workforce, the number of TinyPulse users, and an attacker-claimed file size cannot be converted into a unique affected-person count. pwnCount is therefore zero, meaning that no verified total was published rather than that no employee was affected.\u003C\u002Fp>\n\u003Ch2>Threat-Actor Claims\u003C\u002Fh2>\n\u003Cp>A group calling itself Shadowbyt3$ claimed it stole nearly one gigabyte, demanded two million dollars, and obtained full names, emails, bank statements, W-9 forms, employee IDs, progress plans, and reports. BleepingComputer explicitly said it did not download the allegedly leaked material and could not verify its authenticity.\u003C\u002Fp>\n\u003Cp>Nintendo did not confirm those detailed fields and limited its statement to internal survey content. LeakData therefore excludes the claimed file size, ransom demand, and broad data list from dataClasses and pwnCount. A claim posted on an extortion site is not a definitive inventory unless the company or an independent verified data review confirms it.\u003C\u002Fp>\n\u003Ch2>Information Reported as Unaffected\u003C\u002Fh2>\n\u003Cp>Nintendo emphasized that its systems were not compromised and said no personal customer or financial data was accessed. There is no confirmed impact to Nintendo Account information, gaming accounts, payment details, console data, or customer-support records. Customers were not advised to take account action because of this incident.\u003C\u002Fp>\n\u003Cp>The financial-data exclusion conflicts with the threat actor's allegation about bank statements and W-9 forms. LeakData gives priority to the company confirmation and does not present the unverified actor claim as fact. Nintendo's phrase financial data appears in the customer-data context, so this record does not extend it into a broader absolute claim about every possible employee-survey field.\u003C\u002Fp>\n\u003Ch2>Response and Record Interpretation\u003C\u002Fh2>\n\u003Cp>Nintendo said it was working with the service provider to address the issue. The public statements do not detail how access was terminated, whether passwords or keys were rotated, whether individual employees received notices, or whether regulators were notified. The scope can be updated if a final technical or regulatory account is published.\u003C\u002Fp>\n\u003Cp>The verified conclusion is that mostly older internal survey content belonging to a small subset of Nintendo of America employees was stolen through TinyPulse, while Nintendo systems and customer personal and financial data were unaffected. Employee count, exact fields, initial-access date, and technical method remain undisclosed, and the actor's personal-document and two-million-dollar ransom claims are excluded from definitive fields.\u003C\u002Fp>","Third-party TinyPulse employee survey data theft",false,"Low","completed","\u002Fuploads\u002Flogo\u002Fnintendo_com.png"]