On 17 June, Nintendo of America confirmed that data had been stolen - not from Nintendo's own network, but from TinyPulse, a third-party employee survey and engagement platform owned by WebMD Health Services. The extortion group Shadowbyt3$ claimed to have pulled around 1GB of records spanning 2016 to 2026: full names, email addresses, survey responses, employee IDs, performance progress plans, and - more alarmingly - bank statements and W-9 tax forms. The group first demanded $2 million from Nintendo directly, reported by BleepingComputer, and when Nintendo declined to engage, redirected the ransom demand to TinyPulse itself, according to Nintendo Life. Nintendo's statement was carefully worded: "Nintendo's systems have not been compromised, and no personal customer or financial data has been accessed. The data involved is limited to internal survey content comprising a small subset of our employees."
That statement is true and also slightly beside the point. TechRadar's write-up and Tech Times' account both flag the same detail: a platform most staff would describe, if asked, as "the thing that emails us a survey twice a year" was quietly warehousing a decade of bank details and tax documents. No customer game data was touched. Every employee whose W-9 sat in that archive still has a real problem.
The vendor that isn't on anyone's risk register
Enterprise vendor risk programmes are generally built around the vendors everyone already worries about: the cloud provider, the core banking platform, the outsourced SOC, the AI lab with a data-sharing agreement. Those get security questionnaires, penetration test evidence requests, and a line item in the risk register reviewed at least annually. An employee engagement tool used twice a year by HR to check morale rarely gets the same scrutiny, because it doesn't feel consequential. It doesn't process payments, it doesn't touch production, and nobody thinks of it as holding "real" data.
Except, as this incident shows, it can end up holding exactly the kind of data an attacker wants most: verifiable identity documents tied to real people, with names, bank details and tax IDs, retained for years past the point anyone remembers why. Shadowbyt3$'s method, once the primary target refuses to pay, is to pivot the extortion down to the vendor itself. That is a rational strategy precisely because vendors like TinyPulse sit outside the target company's own security perimeter and, often, outside its own attention.
Two failures stacked on top of each other
Strip the incident down and there are two separate control gaps, and either one alone would have limited the damage. The first is classification: nobody appears to have flagged that an "employee sentiment survey" tool was also a repository of tax and banking documents, which changes its risk tier entirely. The second is retention: data from 2016 has no obvious business reason to still exist in an active, internet-facing SaaS platform in 2026. A decade of accumulated HR records in a tool nobody actively audits is close to a worst-case combination - high sensitivity, low visibility, no expiry.
Neither failure is unique to Nintendo or to TinyPulse. Most enterprises have at least one SaaS tool in a similar position: something HR, facilities, or a regional office signed up for years ago, that quietly accumulated sensitive records because nobody ever went back to ask whether it should keep them.
- List every SaaS tool with access to HR, payroll, or benefits data, regardless of how minor its stated purpose - engagement surveys, wellbeing apps, expense tools, recognition platforms - and tier them by the sensitivity of data they can reach, not by how central they feel to the business.
- Ask each of those vendors, in writing, what their data retention policy actually is, and whether records older than a defined window (12-24 months, for most HR use cases) are deleted rather than archived indefinitely.
- Check whether any of your HR or wellbeing tools request documents like bank statements or tax forms at all - many don't need to, and shouldn't be asked to store them if the underlying process can be redesigned to avoid it.
- Confirm your incident response plan has a defined path for a breach at a vendor-of-a-vendor (TinyPulse is owned by WebMD Health Services), since notification and liability chains get murkier the further removed the ultimate data owner is from the breached party.
- Review whether your vendor risk questionnaire asks about data volume and retention history, not just current security controls - a vendor can pass every technical control and still be sitting on ten years of records it never needed to keep.
Nintendo's statement drew a clean line between "our systems" and "the vendor's systems." Attackers increasingly don't respect that line, and neither should a vendor risk programme that only scores the tools everyone already assumes are dangerous. Want help mapping which SaaS tools in your environment are quietly holding more than anyone remembers approving? Email sales@halfteck.com.