Security1 distinct publisher3 min readUpdated
Pokemon Center and Valve are both writing to European customers about an intrusion at fulfillment provider CEVA Logistics. Neither company's own defenses were the deciding variable.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Pokemon Center and Valve are both writing to European customers about an intrusion at fulfillment provider CEVA Logistics. Neither company's own defenses were the deciding variable.
Follow any of these and your For You feed starts watching them — no settings page required.
Pokemon Center has begun telling customers in the United Kingdom and Germany that their full names, mailing addresses, phone numbers, email addresses and order contents may have been taken from CEVA Logistics, the vendor it uses to ship PokemonCenter.com products into those two markets [1][10]. Valve is sending near-identical notices to European Steam hardware buyers about the same incident [5], which means the variable that determined how many people got a letter was not either retailer's perimeter but how long CEVA keeps delivery data.
According to BleepingComputer, attackers were in CEVA's servers between 29 July and 1 August, affecting multiple retailers in Europe [4]. The Pokemon Center notification email puts the start of the attack at 30 July 2026 [9]. The company says the exposed records belonged to customers who ordered on its site, and that it had passed that data to CEVA in order to fulfill and ship [2]. Pokemon Center adds that no other customer or order information was affected and that CEVA does not hold payment card details [11].
The one number that matters for scoping came from Valve, not from CEVA directly: Valve's notice says CEVA told it that delivery-related information is retained for up to 90 days after an order [6]. It is not clear whether the same window applied to Pokemon Center's data [6]. Set that against CEVA's scale. The provider is a subsidiary of the CMA CGM Group, runs about 1,000 warehouses, handled 15 million shipments last year and reported $18.3 billion in 2025 revenue [3]. A 90-day rolling retention window across that volume is on the order of 3.7 million shipment records resident at any moment, if traffic is spread evenly through the year [16]. Every one of those records sits behind a brand that will have to do the notifying.
The operational damage is separate from the data loss and easier to see. Eight of CEVA's European warehouses were disrupted, producing shipping delays [7]. Pokemon Center's UK site is carrying a notice that some orders will take longer to process, dispatch and deliver [12], while its breach email tells individual customers their order has been cancelled outright "due to an unforeseen fulfilment issue" [8]. Customers say cancellations hit ordinary merchandise, not only the anticipated 30th anniversary line; one Reddit post cites a Ghost Chateau Cyndaquil keyring, and another customer reported the same email [14]. Why an intrusion forces cancellation rather than delay has not been explained [13], and BleepingComputer says it contacted Pokemon Center and Pokemon media contacts without receiving a reply [15].
The practical lesson for anyone with a third-party logistics contract: your notification population is defined by a retention setting in someone else's system, and here it was disclosed by a different customer of that vendor. Worth watching: whether Pokemon Center states the retention period that applied to its own records rather than leaving customers to read Valve's letter [6]; whether more of the European retailers in the affected set start notifying [4]; and whether CEVA itself puts a figure on the records touched, given that so far the scoping detail has come from its clients [6].
Ranked by verification strength, evidence, and original report placement.
Pokemon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics, the vendor Pokemon Center uses to ship PokemonCenter.com products to those markets.
CEVA's systems were compromised, and the exposed records belonged to Pokemon Center customers who submitted orders on the site; Pokemon Center shared that information with the logistics provider to fulfill and ship PokemonCenter.com orders.
CEVA Logistics is a subsidiary of the CMA CGM Group, the world's third-largest shipping company; it operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenue in 2025.
The CEVA breach also affected Valve, which notified Steam hardware customers in Europe that their names, addresses, phone numbers, email addresses, and information about ordered products were stolen during the cyberattack.
The Valve breach notification said CEVA retains delivery-related information for up to 90 days after an order; it is unclear whether the same retention period applies to Pokemon Center customer data.
The attack disrupted eight of CEVA's European warehouses, causing shipping delays for many customers.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Primary notifications reviewed, but single outlet and no vendor confirmation
The reporting quotes breach notification emails it says it reviewed, cites Valve's own notification for the retention window, points to a live delay notice on Pokemon Center's UK site and to customer posts. That is direct documentary grounding for the exposure categories and the cancellations. It is capped by being one publisher, by CEVA and CMA CGM never speaking, by Pokemon Center not replying to questions, and by an unreconciled internal date inconsistency.
Confirmed multi-brand blast radius, unquantified customer scale
Real-world footprint is concrete rather than prospective: two unrelated brands are actively notifying European customers off one intrusion, eight CEVA warehouses were disrupted, a retailer storefront carries a delay notice, and customers report canceled orders across multiple product lines. What is absent is scale - no affected-customer counts, no list of the other affected European retailers, and no confirmed volume of retained records.
Slightly overstated: retention as the deciding variable is inferred, not established
The underlying report is restrained and flags its own uncertainties. The framing that a retention clock set the blast radius runs modestly ahead of the record: the 90-day window comes from Valve's notification and the source explicitly says it is unclear whether it applies to Pokemon Center data, and no disclosed record volume or exposure count ties retention to scope. The gap is small because the reporting itself avoids the stronger claim.
Scope framing comes from the notifying parties; coverage carries a vendor promo
Most substantive detail originates in breach notifications written by companies with an interest in bounding scope - the reassurance that other information was unaffected and that CEVA cannot see payment cards is self-reported and unverified, and the cancellation email frames a security incident as an 'unforeseen fulfilment issue.' The breached vendor and its parent, who bear the liability, say nothing. The article also closes with promotional copy for a commercial security report, an ordinary publisher-monetization interest that does not touch the factual core.
Facts of notification are solid; cause, timing and scale are not
High confidence that Pokemon Center and Valve are notifying European customers about a CEVA intrusion, that the listed data categories are what the notices name, and that warehouse disruption and order cancellations occurred. Materially lower confidence on the intrusion window, on why cancellations were required, on how many customers are affected, and on whether the 90-day retention statement bounds the Pokemon Center dataset - all of which turn on a single publisher and silent principals.
security
Eight warehouses down, six brands notifying: the Ceva outage nobody's plan modelled2 distinct publishers
security
Levi Strauss lost corporate files through three laptops and no malware1 distinct publisher
build
A UDP packet is now enough: IKEEXT RCE moves from patch queue to fire drill1 distinct publisher
leadership
The greenlight moved: where games leadership capacity is actually accumulating1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 17, 2026