Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromise — Threadlinqs Intelligence
As of 2026-08-18, Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromise is a high-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 14 indicators of compromise.
Threat ID: TL-2026-2054 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Pokémon Center is notifying UK and Germany customers of a data breach after third-party shipping vendor CEVA Logistics suffered a cyberattack (~July 29 - August 1, 2026) that compromised systems CEVA
Between roughly July 29 and August 1, 2026, an unattributed threat actor breached systems operated by CEVA Logistics, the France-headquartered contract-logistics arm of shipping group CMA CGM (2025 revenue ~$18.3B, over 1,000 warehouses worldwide). CEVA confirmed the intrusion disrupted at least eight of its European warehouses and that two of the compromised systems processed order/delivery data for retail client Bol's distribution center; CEVA stated the operational impact was contained to those eight sites and that no other CEVA systems globally were affected. CEVA has not publicly disclosed the initial-access vector, the volume of records taken, whether a ransom was demanded, or attributed the intrusion to a specific actor; the company did not respond to press inquiries from The Register, SecurityWeek, or TechCrunch about attack methodology.
Because CEVA operates as a shared data processor for many unrelated retail, financial, sporting, and gaming brands' European order-fulfillment pipelines, the single intrusion cascaded into a multi-tenant breach: Dutch e-commerce giant Bol, luxury department store De Bijenkorf, eyewear retailer Ace & Tate, football club AFC Ajax, bank ING, e-commerce firm Zalando, and Valve Corporation (Steam hardware shipments — Steam Machines, Steam Controllers, Steam Deck units) all confirmed exposure of customer records tied to CEVA-processed orders. Ten or more organizations reported the breach to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) as controllers under GDPR, with CEVA acting as their shared processor. Valve stated it learned of the likely compromise on August 7, 2026 and notified customers August 10; it retains CEVA-processed delivery data for 90 days post-order, defining its exposure window. Pokémon Center — which uses CEVA to fulfill PokemonCenter.com orders in the UK and Germany — began notifying affected customers August 18, 2026, and canceled a number of in-flight orders (including 30th Anniversary Collection items and the Ghost Chateau Cyndaquil keyring) as a result, without a public explanation for why cancellation rather than delay was necessary.
Exposed data across the affected organizations consistently comprises full names, mailing addresses/postcodes, phone numbers, email addresses, order numbers, shipment tracking information, order contents/pricing details, and — for at least one retail client — gift-card message text attached to orders; no payment card data, bank account numbers, Steam credentials/Steam Guard codes, or passwords were exposed, as CEVA's systems never had access to that data. CEVA has stated it isolated the affected systems and engaged external investigators as part of its response, and that transportation operations continued uninterrupted throughout. A compliance analysis of the incident (ComplianceHub) reconstructs a notification chain in which CEVA disclosed to customers/controllers on August 1, the Dutch DPA was informed by August 3, some controllers emailed data subjects by August 5 (a four-day gap from CEVA's own disclosure), and Valve independently discovered the compromise on August 7 — illustrating how a processor-side breach compresses each controller's independent 72-hour GDPR Article 33 notification clock, with additional 24-hour/72-hour NIS2 reporting obligations attaching to CEVA itself as a high-criticality transport-sector entity, and DORA obligations attaching to affected financial entities like ING.
Valve's customer notification explicitly warned that the leaked name/address/order data will make follow-on impersonation fraud unusually convincing: affected customers should expect phishing by email, SMS, and phone that impersonates Steam, Valve, or delivery couriers, quotes the victim's real address back to them to appear legitimate, and asks them to confirm a delivery, pay a small fake customs/redelivery fee, or sign in somewhere to "verify" an order. Valve stressed customers do not need to change Steam passwords or a
Target sectors: retail, ecommerce, gaming, banking, financial services, sports and entertainment, eyewear consumer goods, logistics and transportation
Target regions: Europe, united kingdom, germany, netherlands
Detections & IOCs
As of 2026-08-20, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 14 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1199, T1213, T1589, T1566, T1566.002, T1660, T1598.004, T1204.001, T1684.001, T1657