:

NINTENDO CONFIRMS DATA THEFT IN TINYPULSE BREACH

SECURITY DESK■ 1 MIN READ
FRI, JUN 19, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

Nintendo of America confirmed that threat actors stole survey data from TinyPulse, a third-party service used internally by the company. Nintendo's own systems were not compromised in the incident.

The stolen data came from TinyPulse, an employee engagement platform used by Nintendo for internal surveys. The breach affected the WebMD subsidiary's systems, though details on the scope of compromised information remain limited. Nintendo emphasized that the intrusion was contained to the third-party service and did not extend to its core infrastructure or customer-facing systems. The company has not disclosed the number of affected employees or specific details about the survey data accessed. The incident underscores ongoing risks associated with third-party service providers, even when direct company systems remain secure. Nintendo joins a growing list of major organizations affected by breaches involving external vendors and contractors. No indication has been provided regarding which threat actors were responsible or whether they attempted to exploit the data publicly.

■ SOURCES

► Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

License plate camera company Flock Safety once promoted its devices as American-made, but the company now provides little clarity on where cameras are actually assembled. The shift raises questions about supply chain transparency and potential cybersecurity risks.

2H AGO— Industry Desk

Chinese espionage group FamousSparrow is using a new backdoor malware called SparroWocky to target government organizations across Latin America.

3H AGO— Security Desk

A reverse-engineering enthusiast has successfully broken Sony's original PlayStation 2 security chip after four years of effort. The CXP102064 MechaCon chip, which protected the console from unauthorized software, has been fully unlocked.

3H AGO— Security Desk

Cisco has released security updates for a critical Identity Services Engine vulnerability being actively exploited by attackers. The zero-day flaw carries a CVSS score of 10.0, indicating maximum severity.

5H AGO— Security Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.