Nintendo confirms data stolen in WebMD subsidiary cyberattack

2026-06-18T19:23:27Z243ad514812e6f30e76dbc3001f4ef9419244d709c9070acf8196d6ae9422507
apple-beatsbeets-studio-budsbluetoothclipboard-stealercredential-leakcrypto-stealerdata-theftevil-corpf5fortibleedfortinetincident-responsenginxoauth-breachout-of-band-patchsalesforceshapedpluginsocgholishsupply-chaintelecom-blockingusb-wormwordpress

What happened

Multiple high-impact security events reported on 18 Jun 2026: a data-theft incident at TinyPulse (affecting Nintendo survey data) linked to a WebMD subsidiary breach; a self-spreading USB worm distributing clipboard‑stealer crypto malware over Windows shortcut (.lnk) files with Tor-based C2; an OAuth compromise at Klue used by the "Icarus" actors to exfiltrate Salesforce CRM data; a supply‑chain compromise of ShapedPlugin updates infecting WordPress sites; and a large FortiBleed leak exposing VPN credentials for ~73,932 Fortinet/FortiGate URLs. Separately, law enforcement removed ~15,000 SocGh

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
243ad514812e6f30e76dbc3001f4ef9419244d709c9070acf8196d6ae9422507
Enrichment time
2026-06-18T19:23:27Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Nintendo confirms data stolen in WebMD subsidiary cyberattack · Baitaphish