Hacking into a company database, stealing customer data, and using the information to blackmail corporate executives never seems to have a favorable outcome for the hackers. That, however, doesn’t seem to dissuade certain people from thinking they can actually pull it off themselves.
Such is the case of a man in Spain who tried to blackmail gaming-giant Nintendo in a similar fashion.

Reports from news outlet El Mundo indicate that Spanish police have arrested a man in the province of Malaga for taking advantage of a flaw in one of the company’s websites, stealing the data of over 4,000 subscribers, and making demands to Nintendo representatives. The man, who reportedly went by the screen name 'adan_gecko', claims that it was concern for user security that prompted him to contact Nintendo and threaten to release the data online, as well as contact the country’s Data Protection Agency if his demands were not met. Details regarding what specifically the man had demanded from the company have not yet been released.
The website in question was reportedly a promotional forum to support the release of Nintendo’s new 3DS handheld gaming device. The man claimed that the site security was so bad that he was easily able to access the site’s user database simply by substituting part of the URL with “admin”. He also states that he only planned to release the data and file his complaint because the company had not responded to his emails.
A Nintendo spokesperson stressed that the company had taken steps to correct the issue, and that it was not as simple to access the data as the man had claimed. The company states that "independent external expertise" has verified that the man had employed “various techniques of hacking” in his quest to steal the information.
The man, however, claims that Nintendo’s complaints against him contain several “factual inaccuracies”, and that they had failed to resolve the issue within a 48-hour time-frame of his notifications.
Meanwhile, Spain’s Data Protection Agency has opened an investigation into whether the design of Nintendo’s promotional website may have contained flaws that too easily exposed user’s information.
While data security is certainly an important matter, threats of blackmail and posting private data on internet forums is rarely a constructive means to address security weaknesses. No matter what Nintendo may have done wrong in this case, fighting crime with crime is not an acceptable resolution to the problem.















