NINTENDO OF AMERICA INC.
bd_e5878a31d925044b · schema v1 · pii pii-v2
Full breach record for NINTENDO OF AMERICA INC. →5 incidents on fileThreat-actor claim — not a regulatory filing
This row is a claim by the ransomware group Shadowbyt3$ on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.
Source: Ransomware.live
Post text · scraped from the leak site
proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extortion as a service group. We stole close enough to 1gb. You have 48 hours to contact us nintendo or all data gets leaked. If you contact us we give you an extra day to think this through. We are demanding a ransom payment of 2 million dollars. Check your inbox if you work for nintendo and use TINYpulse or go login to tinypulse if the url in the leak looks familiar. You have 48 hours from this announcement then it gets leaked. You have till June 15 2026. size: 859.0MB Close enough to 1GB it contains the following: -full name first name, last name, email of employees -analytics - surveys - all reports exported - all bank statements of payment pdf and w9 forms with employee ids - all cheers exported - all wins dashboard and wall of wins exported - all progress plans exported - Reports from 2016 to up to date 2026 - Analytics of Employees contain conversations and personal feelings about work and more - Content library of personal questions and engagement analytics - TINYpulse and Nintendo top employees of Nintendo based on engagement
J jump to incidentP pin to compareR raw source
Incident timeline — mostly unverified
? — ?
Breach window unknown
Jun 12, 2026
Claim posted
—
Corroborated · see linked filings
Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.
Claim → filing
—
Compliance clock
Not assessable
Linked disclosures
Why this link?Ransomware claims (1)
- Leak Siteshadowbyt3$bd_7e1954d36b8493da2026-06-12Candidate
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.
Source ceiling
- actor name
- victim claim
- ransom/leak status
- discovery date
- materiality
- notification
- affected count
- confirmed data types
- compliance clock
The ✕ fields stay blank until a regulatory filing or victim disclosure lands.
shadowbyt3$
According to ransomware.live, ShadowByt3$ is a ransomware-as-a-service group first observed in October 2025, using multi-method extortion and communicating via Telegram and Tox, with a very small confirmed victim list suggesting it remains in early-stage operation.