DisclosureLens
GLOBALMalwareTechnologyInformationRansomwareShadowbyt3$Shadowbyt3Ransom DemandedActor NamedData Leak ThreatenedData PublishedHigh

NINTENDO OF AMERICA INC.

bd_aa7556dc5bc22f0a · schema v1 · pii pii-v2

Severity

High

Discovered

Filed

Aug 25, 2026

To disclose

Affected

Not disclosed

Linked

2 filings

Confidence

50%

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group Shadowbyt3$ on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: TechnologyDiscovered: 2026-08-25

Source: Ransomware.live

Post text · scraped from the leak site

This will be quick. You don't even want to read the private messages as some will be embarrasing. Some people are confused but this breach doesn't affect you unless if you use tinypulse and work for nintendo. There will be more victims coming soon. If you get a email by us. by us we mean are only email on are leak site, then respond or it will get leaked. We will send file trees for confirmation to prove we actually breached your company. It's pretty funny how companies are defending themselves and when the truth comes out now they want to stay quiet. We have no further questions to answer. This is a warning to all companies if you get breached by us, It's best to contact us especially if we show you the file size. This was true negligence and now you will likely face a massive lawsuit, have fun tinypulse and told you this would be quick. uncompressed file size: (856MB) compressed size: (6.89MB) The included data includes: - full name, first name, last name, email (the w9 is only one and multiple invoices) - Private Employee Chats: Direct internal messages and conversations between workers. - Mar 10, 2025 Sure, it's Knowledge Team—we've needed more content creators for years, but it seems all we can ever get approved are more associates, often temporarily. This helps some, and I know there are vague rumors that maybe we will be able to swap our associates over to NOA employees in the future, but that's not what we need—we need more writers so that we can distribute the primary work among more people. overworking chat: Sep 22, 2025 How happy are you at work? 3 I'm generally extremely content, but the overwhelming number of overlapping high-priority projects and a constant stream of meetings, has left me with little to no available occupancy. This has made it tough to manage everything effectively and still make time for innovation.

Incident timeline — mostly unverified

? — ?

Breach window unknown

Aug 25, 2026

Claim posted

Corroborated · see linked filings

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

This filing is one of 2 about the same incident.View merged incident

Linked disclosures

Why this link?

Ransomware claims (1)

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2026-02-17

shadowbyt3$

According to ransomware.live, ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.

31 tracked hereFull profile →