:

NINTENDO CONFIRMS DATA THEFT IN TINYPULSE BREACH

SECURITY DESK■ 1 MIN READ
FRI, JUN 19, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Nintendo of America confirmed that threat actors stole survey data from TinyPulse, a third-party service used internally by the company. Nintendo's own systems were not compromised in the incident.

The stolen data came from TinyPulse, an employee engagement platform used by Nintendo for internal surveys. The breach affected the WebMD subsidiary's systems, though details on the scope of compromised information remain limited. Nintendo emphasized that the intrusion was contained to the third-party service and did not extend to its core infrastructure or customer-facing systems. The company has not disclosed the number of affected employees or specific details about the survey data accessed. The incident underscores ongoing risks associated with third-party service providers, even when direct company systems remain secure. Nintendo joins a growing list of major organizations affected by breaches involving external vendors and contractors. No indication has been provided regarding which threat actors were responsible or whether they attempted to exploit the data publicly.

■ SOURCES

► Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

File transfer platform Kiteworks has urged customers to shut down their servers after receiving a credible threat of an imminent cyberattack from law enforcement.

JUST NOW— Security Desk

Cryptocurrency exchange Bitget disclosed a breach of its hot and warm wallets, with hackers stealing $351.6 million. The attack is attributed to suspected North Korean threat actors.

2H AGO— Security Desk

A Kosovar national has pleaded guilty to operating Rydox, an illegal online marketplace that trafficked in stolen personal information, login credentials, and cybercrime tools. The admin faces up to 22 years in prison.

4H AGO— Industry Desk

Scammers are spoofing popular invitation platforms like Evite and Paperless Post to steal personal data. The deceptive emails are convincing enough that some recipients use them as opportunities to reconnect with old contacts.

4H AGO— Security Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.