Skip to content

Security1 publisher3 min readPublished

One warehouse breach, two brands notifying: CEVA's retention clock set the blast radius

Pokemon Center and Valve are both writing to European customers about an intrusion at fulfillment provider CEVA Logistics. Neither company's own defenses were the deciding variable.

The Watch · Security desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Photograph accompanying One warehouse breach, two brands notifying: CEVA's retention clock set the blast radius
Photo: esecurityplanet.com

What happened

  • Pokemon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics, the vendor Pokemon Center uses to ship PokemonCenter.com products to those markets.
  • CEVA's systems were compromised, and the exposed records belonged to Pokemon Center customers who submitted orders on the site; Pokemon Center shared that information with the logistics provider to fulfill and ship PokemonCenter.com orders.
  • CEVA Logistics is a subsidiary of the CMA CGM Group, the world's third-largest shipping company; it operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenue in 2025.
  • CEVA recently suffered a cyberattack in which attackers breached its servers between July 29 and August 1, affecting multiple retailers in Europe.
  • The CEVA breach also affected Valve, which notified Steam hardware customers in Europe that their names, addresses, phone numbers, email addresses, and information about ordered products were stolen during the cyberattack.

Compiled by The WatchSomething wrong?How this is made

Why it matters

Pokemon Center has begun telling customers in the United Kingdom and Germany that their full names, mailing addresses, phone numbers, email addresses and order contents may have been taken from CEVA Logistics, the vendor it uses to ship PokemonCenter.com products into those two markets [1][10]. Valve is sending near-identical notices to European Steam hardware buyers about the same incident [5], which means the variable that determined how many people got a letter was not either retailer's perimeter but how long CEVA keeps delivery data.

According to BleepingComputer, attackers were in CEVA's servers between 29 July and 1 August, affecting multiple retailers in Europe [4]. The Pokemon Center notification email puts the start of the attack at 30 July 2026 [9]. The company says the exposed records belonged to customers who ordered on its site, and that it had passed that data to CEVA in order to fulfill and ship [2]. Pokemon Center adds that no other customer or order information was affected and that CEVA does not hold payment card details [11].

The one number that matters for scoping came from Valve, not from CEVA directly: Valve's notice says CEVA told it that delivery-related information is retained for up to 90 days after an order [6]. It is not clear whether the same window applied to Pokemon Center's data [6]. Set that against CEVA's scale. The provider is a subsidiary of the CMA CGM Group, runs about 1,000 warehouses, handled 15 million shipments last year and reported $18.3 billion in 2025 revenue [3]. A 90-day rolling retention window across that volume is on the order of 3.7 million shipment records resident at any moment, if traffic is spread evenly through the year [16]. Every one of those records sits behind a brand that will have to do the notifying.

The operational damage is separate from the data loss and easier to see. Eight of CEVA's European warehouses were disrupted, producing shipping delays [7]. Pokemon Center's UK site is carrying a notice that some orders will take longer to process, dispatch and deliver [12], while its breach email tells individual customers their order has been cancelled outright "due to an unforeseen fulfilment issue" [8]. Customers say cancellations hit ordinary merchandise, not only the anticipated 30th anniversary line; one Reddit post cites a Ghost Chateau Cyndaquil keyring, and another customer reported the same email [14]. Why an intrusion forces cancellation rather than delay has not been explained [13], and BleepingComputer says it contacted Pokemon Center and Pokemon media contacts without receiving a reply [15].

The practical lesson for anyone with a third-party logistics contract: your notification population is defined by a retention setting in someone else's system, and here it was disclosed by a different customer of that vendor. Worth watching: whether Pokemon Center states the retention period that applied to its own records rather than leaving customers to read Valve's letter [6]; whether more of the European retailers in the affected set start notifying [4]; and whether CEVA itself puts a figure on the records touched, given that so far the scoping detail has come from its clients [6].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories