A ransomware group is reportedly demanding $2 million from Nintendo in connection with an alleged breach involving TINYpulse employee data. Multiple outlets report that Nintendo has acknowledged an “issue involving TinyPulse,” but says the impact is limited. Nintendo tells Kotaku it is aware of the situation and states that there is no exposure of personal customer or financial information. Video Games Chronicle also reports Nintendo’s position that the stolen employee data is “limited and old,” suggesting that the compromised material is not current and does not materially expand the scope of risk.
The ransomware group’s request centers on preventing the release of data it claims it obtained from Nintendo through the TINYpulse-related incident. While reporting varies in characterizations and details of what was taken, the common elements across sources are the ransomware demand amount, Nintendo’s acknowledgment of a TinyPulse-related problem, and Nintendo’s assertion that customer and financial data are not involved. The situation remains under discussion as outlets summarize what Nintendo has publicly indicated and what the attackers have claimed.