The post has been translated automatically. Original language: Russian
Nintendo and Hacking through HR services: Why Third-party SaaS Platforms are also part of Your Security
In June 2026, Nintendo of America confirmed an incident related not to its internal systems, gaming services, or customer base, but to the third-party TINYpulse platform. This service was used for internal employee surveys. According to Nintendo, the company's own systems were not compromised, and customer and financial data were not affected. Some of the internal survey data of a small number of employees was accessed, and most of the information related to previous years.
At first glance, the case does not look as large-scale as attacks on manufacturing, banks or medical companies. But this is precisely its value: it shows that the weak point may not be the main server, website, or payment system, but an ordinary SaaS tool used by HR, marketing, finance, or customer support.
What happened
Nintendo confirmed to BleepingComputer that the data was stolen from TINYpulse, a third—party service for internal employee surveys. The company separately emphasized that its own systems had not been hacked, and it was talking about a limited set of internal data related to employee surveys.
The incident became public after the statements of the Shadowbyt3$ group. According to BleepingComputer, the group claimed to have received almost 1 GB of data and demanded $2 million, threatening to publish the files. Among the data claimed by the attackers were names, email addresses, analytics, survey data, bank documents, W-9 forms, employee ID, development plans and reports for the period from 2016 to 2026. These claims come from attackers, so it's important to treat them carefully: Nintendo has only confirmed limited access to internal survey content.
Cybernews wrote that the researchers examined the data samples and found signs that some of the materials could be genuine: among them were employee engagement surveys, workplace feedback, and mentions of employees who, according to the publication, could still work at Nintendo. But the full scale and composition of the leak remains a matter of verification.
Why is this important
Companies often build protection around obvious assets: corporate network, website, CRM, ERP, payments, customer bases, and cloud infrastructure. But in reality, the data has long been distributed across dozens of external services.
HR uses platforms for surveys, performance review, and onboarding. Marketing — mailing, analytics, and lead generation services. Finance — cloud-based reporting tools. Support — helpdesk platforms. Legal and procurement — document management and contractor management systems.
Each such service can store internal data. These are not always payment information or passwords. Sometimes these are employee comments, organizational structure, development plans, internal reports, team sentiment data, email addresses, roles, and workflows. For attackers, this is enough to put pressure on the company, prepare phishing or build more accurate attacks.
Why HR data is sensitive
HR data is often underestimated. It seems that employee surveys are not a trade secret or a customer base. But in a corporate environment, such information can be quite sensitive.
Internal survey data shows what employees are dissatisfied with, which teams are under strain, where there are problems with management, what processes are stalling and what topics are being discussed within the company. If names, email addresses, employee IDs, or financial documents are added to this, the risk becomes higher.
Such data can be used for phishing. For example, an attacker may write an employee not an abstract letter, but a message with context: mention a department, an internal project, an HR process, or a recent survey. The more details, the more convincing the attack.
What the Nintendo case shows
The first conclusion is that the company's security does not end with its own infrastructure. Even if the internal servers are protected, data can leak through an external service.
The second conclusion is that SaaS platforms need to be included in the risk map. If a service stores employee, customer, finance, development, or internal process data, it must undergo a regular security assessment.
The third conclusion is that it is important to understand the data retention period. In this case, the attackers claimed that the data covered the period from 2016 to 2026. Even if some of the information is old, it can remain useful: email addresses, internal formulations, roles, team structure, and document templates often live for years.
The fourth conclusion is that data minimization is just as important as perimeter protection. If the service does not need to store old reports for years, they should be deleted or archived with additional access restrictions.
What companies should check out
The first is a list of all external SaaS services. The company should have an up-to-date register of tools used by HR, marketing, sales, finance, support, IT and other departments.
The second is what data is transmitted there. It is necessary to understand where personal data of employees, internal reports, contracts, financial documents, client information and project data are stored.
The third is who has access. The principle of minimum privileges should be applied not only within the corporate network, but also in external services. The access rights of former employees, contractors, and temporary users should be reviewed regularly.
The fourth is what requirements are prescribed in contracts with suppliers. It is important to determine in advance how the provider notifies about the incident, which event logs are available to the client, how the data is stored, where the data centers are located, and what happens to the information after the service is discontinued.
The fifth is how offboarding works. If an employee leaves the company, their access should be closed not only in corporate mail and VPN, but also in all third-party SaaS tools.
Why does this apply not only to large companies
Nintendo is a recognizable brand, so the case got into the news. But companies of any size have the same problem. Small businesses, startups, and corporate teams use dozens of cloud services, often without a full-fledged vendor risk management.
The problem is that SaaS is easy to connect, but harder to control. One department may start using a new tool without consulting IT. Another option is to upload a table with employee data there. The third option is to forget to delete old reports. After a few years, no one remembers exactly where the data is, but a weak service is enough for the attackers.
The main conclusion
The Nintendo case shows that it's not necessary to hack into a company's central infrastructure to create risk. Sometimes it is enough to get access to a third-party platform where internal employee data is stored.
For businesses, this means that third-party risk and SaaS security should be part of an overall cybersecurity strategy. External services need to be taken as seriously as servers, network, clouds, and applications.
The main question after such incidents is simple: what data of our company does external services have today — and will we find out about the leak before the attackers write about it?
Nintendo и инцидент у HR-сервиса: почему SaaS-платформы входят в контур киберрисков
В июне 2026 года Nintendo of America подтвердила инцидент, связанный со сторонним сервисом TinyPulse. Платформа использовалась для внутренних опросов сотрудников. По данным SC Media, собственные системы Nintendo не были затронуты, а инцидент был связан именно с внешним сервисом для employee surveys.
Кейс важен не масштабом, а типом риска. Он показывает, что корпоративные данные могут находиться не только в CRM, ERP, почте, облачной инфраструктуре или внутренних системах, но и во внешних SaaS-платформах, которые используют отдельные подразделения.
Что произошло
Инцидент был связан с TinyPulse — сервисом, который используют для опросов сотрудников и оценки вовлеченности. Nintendo подтвердила, что речь идет о данных, связанных с внутренними опросами, при этом ее собственная инфраструктура и клиентские данные не были скомпрометированы.
Это важная деталь. Компания может не быть затронута напрямую, но ее данные все равно могут оказаться под риском, если они хранятся или обрабатываются у внешнего поставщика.
Почему это касается не только Nintendo
Компании часто фокусируют защиту на самых очевидных активах: корпоративной сети, сайте, клиентской базе, платежных системах, ERP, CRM и облачных сервисах. Но в реальной работе данные распределены по большому числу внешних платформ.
HR использует сервисы для опросов, онбординга и оценки сотрудников. Маркетинг — инструменты рассылок и аналитики. Финансы — облачные решения для отчетности. Поддержка — helpdesk-платформы. Юридические и закупочные команды — системы документооборота и работы с подрядчиками.
Каждый такой сервис становится частью цифрового контура компании. Даже если он не хранит клиентские платежи или пароли, в нем могут находиться внутренние отчеты, корпоративные email-адреса, роли сотрудников, результаты опросов, организационная структура и рабочий контекст.
Почему HR-данные нельзя считать второстепенными
HR-данные часто воспринимаются как менее критичные, чем финансовая отчетность или клиентская база. Но внутренние опросы сотрудников могут раскрывать важный контекст: какие команды перегружены, какие процессы вызывают сложности, какие темы обсуждаются внутри компании и где есть организационные проблемы.
Такая информация может быть чувствительной даже без прямого доступа к клиентским данным. Она помогает понять структуру компании, внутренние процессы и рабочие связи между командами.
Если к этому добавляются имена, корпоративные адреса, должности или внутренние идентификаторы, риск становится выше. Эти данные могут использоваться для более точной социальной инженерии или попыток получить доступ к другим системам.
Что показывает этот кейс
Первый вывод — безопасность компании не заканчивается на ее собственных системах. Если данные передаются внешнему сервису, этот сервис тоже становится частью риск-модели.
Второй вывод — SaaS-платформы нужно учитывать в общей карте активов. Компания должна понимать, какие внешние инструменты используют разные подразделения и какие данные туда загружаются.
Третий вывод — срок хранения данных имеет значение. Даже устаревшая информация может оставаться полезной: корпоративные адреса, должности, внутренние формулировки, структура команд и отчеты часто сохраняют ценность дольше, чем кажется.
Четвертый вывод — минимизация данных снижает последствия инцидента. Если сервису не нужно хранить старые отчеты годами, их стоит удалять, архивировать или ограничивать к ним доступ.
Что стоит проверить компаниям
Первое — реестр внешних сервисов. У компании должен быть актуальный список SaaS-платформ, которые используют HR, маркетинг, финансы, продажи, поддержка, юридический отдел и другие команды.
Второе — состав данных. Важно понимать, какие данные передаются во внешний сервис: персональная информация сотрудников, внутренние отчеты, финансовые документы, клиентская информация, договоры или проектные материалы.
Третье — доступы. Принцип минимальных привилегий должен применяться не только внутри корпоративной сети, но и во внешних платформах. Доступы бывших сотрудников, подрядчиков и временных пользователей нужно регулярно пересматривать.
Четвертое — условия работы с поставщиком. В договорах и внутренних процедурах должны быть понятны правила хранения данных, сроки удаления информации, порядок уведомления об инцидентах, доступность журналов событий и ответственность сторон.
Пятое — offboarding. При увольнении сотрудника доступы должны закрываться не только в корпоративной почте, VPN и внутренних системах, но и во всех сторонних SaaS-инструментах.
Почему SaaS-риски часто остаются незаметными
SaaS-сервис легко подключить: достаточно регистрации, подписки и загрузки данных. Поэтому отдельные отделы могут начать использовать внешний инструмент без полноценной оценки рисков.
Через несколько месяцев или лет становится сложно быстро ответить, какие данные туда загружались, кто имел доступ и удалялись ли старые материалы. Так появляется shadow IT — сервисы, которые фактически используются в работе, но не полностью контролируются IT- или security-командой.
Проблема не в самом использовании SaaS. Такие инструменты помогают компаниям работать быстрее. Риск возникает тогда, когда организация не видит, где находятся ее данные и кто отвечает за их защиту.
Главный вывод
Инцидент с TinyPulse показывает, что киберриски могут возникать не только в основной инфраструктуре компании. Иногда достаточно проблемы у стороннего сервиса, чтобы внутренние корпоративные данные оказались под угрозой.
Для бизнеса это означает, что управление рисками должно включать не только серверы, сеть, облака и приложения, но и внешние платформы, которыми пользуются разные подразделения.
Главный вопрос после таких ситуаций простой: какие данные компании сегодня находятся у внешних сервисов — и насколько быстро организация сможет понять масштаб риска, если один из этих сервисов будет затронут инцидентом?