Threat reportData BreachTL-2026-2054

Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromise

highACTIVE

Pokémon Center Confirms Customer Data Breach via CEVA (TL-2026-2054) is a high-severity data breach, first published 2026-08-18. It has no confirmed attribution, affects CEVA Logistics (CMA CGM subsidiary) European contract-logistics, maps to 10 MITRE ATT&CK techniques (T1199, T1204.001, T1213), and is covered by 9 detection rules and 14 indicators of compromise.

Severity
HIGHAssessed severity
CVEs
0None referenced
Techniques
10MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
14Indicators of compromise

Key facts for TL-2026-2054

Threat ID
TL-2026-2054
Severity
HIGH
Status
ACTIVE
Category
DATA_BREACH
First published
Last reviewed
Attribution confidence
LOW
Motivation
UNKNOWN
Target sectors
retail, ecommerce, gaming, banking, financial services, sports and entertainment, eyewear consumer goods, logistics and transportation
Target regions
Europe, united kingdom, germany, netherlands
Detection rules
9
Indicators of compromise
14

How Pokémon Center Confirms Customer Data Breach via CEVA works

Pokémon Center is notifying UK and Germany customers of a data breach after third-party shipping vendor CEVA Logistics suffered a cyberattack (~July 29 - August 1, 2026) that compromised systems CEVA uses to process delivery information for retail clients. The same intrusion rippled into at least nine other CEVA clients across banking, retail, sport, eyewear, and gaming, and disrupted eight European CEVA warehouses.

Between roughly July 29 and August 1, 2026, an unattributed threat actor breached systems operated by CEVA Logistics, the France-headquartered contract-logistics arm of shipping group CMA CGM (2025 revenue ~$18.3B, over 1,000 warehouses worldwide). CEVA confirmed the intrusion disrupted at least eight of its European warehouses and that two of the compromised systems processed order/delivery data for retail client Bol's distribution center; CEVA stated the operational impact was contained to those eight sites and that no other CEVA systems globally were affected. CEVA has not publicly disclosed the initial-access vector, the volume of records taken, whether a ransom was demanded, or attributed the intrusion to a specific actor; the company did not respond to press inquiries from The Register, SecurityWeek, or TechCrunch about attack methodology.

Because CEVA operates as a shared data processor for many unrelated retail, financial, sporting, and gaming brands' European order-fulfillment pipelines, the single intrusion cascaded into a multi-tenant breach: Dutch e-commerce giant Bol, luxury department store De Bijenkorf, eyewear retailer Ace & Tate, football club AFC Ajax, bank ING, e-commerce firm Zalando, and Valve Corporation (Steam hardware shipments — Steam Machines, Steam Controllers, Steam Deck units) all confirmed exposure of customer records tied to CEVA-processed orders. Ten or more organizations reported the breach to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) as controllers under GDPR, with CEVA acting as their shared processor. Valve stated it learned of the likely compromise on August 7, 2026 and notified customers August 10; it retains CEVA-processed delivery data for 90 days post-order, defining its exposure window. Pokémon Center — which uses CEVA to fulfill PokemonCenter.com orders in the UK and Germany — began notifying affected customers August 18, 2026, and canceled a number of in-flight orders (including 30th Anniversary Collection items and the Ghost Chateau Cyndaquil keyring) as a result, without a public explanation for why cancellation rather than delay was necessary.

Exposed data across the affected organizations consistently comprises full names, mailing addresses/postcodes, phone numbers, email addresses, order numbers, shipment tracking information, order contents/pricing details, and — for at least one retail client — gift-card message text attached to orders; no payment card data, bank account numbers, Steam credentials/Steam Guard codes, or passwords were exposed, as CEVA's systems never had access to that data. CEVA has stated it isolated the affected systems and engaged external investigators as part of its response, and that transportation operations continued uninterrupted throughout. A compliance analysis of the incident (ComplianceHub) reconstructs a notification chain in which CEVA disclosed to customers/controllers on August 1, the Dutch DPA was informed by August 3, some controllers emailed data subjects by August 5 (a four-day gap from CEVA's own disclosure), and Valve independently discovered the compromise on August 7 — illustrating how a processor-side breach compresses each controller's independent 72-hour GDPR Article 33 notification clock, with additional 24-hour/72-hour NIS2 reporting obligations attaching to CEVA itself as a high-criticality transport-sector entity, and DORA obligations attaching to affected financial entities like ING.

Valve's customer notification explicitly warned that the leaked name/address/order data will make follow-on impersonation fraud unusually convincing: affected customers should expect phishing by email, SMS, and phone that impersonates Steam, Valve, or delivery couriers, quotes the victim's real address back to them to appear legitimate, and asks them to confirm a delivery, pay a small fake customs/redelivery fee, or sign in somewhere to "verify" an order. Valve stressed customers do not need to change Steam passwords or account settings, since account credentials were never part of the exposure. Multiple outlets (Malwarebytes, RespawnFirst, FinalBoss) independently amplified this warning; no outlet has yet reported an observed, in-the-wild phishing campaign specifically tied to this data, only the anticipated risk flagged by Valve.

Context: CEVA Logistics was previously compromised in a distinct, unrelated September 2025 incident claimed by the extortion group 'Coinbase Cartel,' which exploited an exposed FortiOS SSL-VPN credential set (CVE-2022-40684 / FortiBleed) to access CEVA employee and third-party credentials. That 2025 incident is a separate confirmed compromise of the same recidivist vendor and is cited here only as precedent for CEVA's recurring targeting; no source ties CVE-2022-40684 or Coinbase Cartel to the July-August 2026 breach, and this record does not attribute the current intrusion to that vector or actor.

MITRE ATT&CK techniques used in TL-2026-2054

Initial Access

T1199 Trusted Relationship; T1566 Phishing; T1566.002 Spearphishing Link; T1660 Phishing

Execution

T1204.001 Malicious Link

Collection

T1213 Data from Information Repositories

Reconnaissance

T1589 Gather Victim Identity Information; T1598.004 Spearphishing Voice

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in Pokémon Center Confirms Customer Data Breach via CEVA

  • CEVA Logistics (CMA CGM subsidiary) — European contract-logistics order/delivery-processing systems
    Vulnerable versions: 8 CEVA warehouses in Europe, systems processing orders during Jul 29 - Aug 1 2026
  • The Pokémon Company International / Pokémon Center — PokemonCenter.com order fulfillment for UK and Germany (delivery data shared with CEVA)
    Vulnerable versions: Orders processed via CEVA during the Jul 29 - Aug 1 2026 compromise window
  • Valve Corporation — Steam Hardware (Steam Machine, Steam Controller, Steam Deck) European shipping via CEVA
    Vulnerable versions: Orders within CEVA's 90-day delivery-data retention window as of the breach

Remediation for Pokémon Center Confirms Customer Data Breach via CEVA

Immediate actions

  • Affected individuals: treat unsolicited email/SMS/voice contact referencing a real CEVA-processed order as suspicious even if it quotes accurate name/address/order details back to you
  • Do not pay 'customs' or 'redelivery' fees requested via unsolicited delivery-notification messages; verify independently via the retailer's official site/app
  • Do not click links in unsolicited delivery/order-verification messages or enter credentials on pages reached from them
  • Affected controllers (retailers/banks/etc.): complete GDPR Article 33/34 notifications to national DPAs and data subjects on an independent clock from the processor's own disclosure timeline

Workarounds

  • No password/account changes required for Steam, Pokémon Center, or other affected retail accounts — no credentials, payment data, or account passwords were exposed per all affected companies' statements

Longer-term hardening

  • Map and inventory shared third-party logistics/fulfillment processors as concentration-risk single points of failure across otherwise unrelated business lines
  • Contractually require processors (CEVA and similar) to commit to hour-scoped breach-notification SLAs (e.g., 24h) rather than 'without undue delay' language
  • Minimize and time-box retention of delivery/order PII held by third-party logistics processors (Valve's 90-day retention window defined its own exposure scope)
  • Coordinate cross-controller incident response when a shared processor is breached, given NIS2 (transport sector) and DORA (financial entities) reporting obligations may run in parallel with GDPR

Timeline of Pokémon Center Confirms Customer Data Breach via CEVA

  • Distinct, unrelated 2025 incident: extortion group 'Coinbase Cartel' claims a breach of CEVA Logistics via exposed FortiOS SSL-VPN credentials (CVE-2022-40684/FortiBleed), compromising employee and third-party credentials — cited as precedent for CEVA's recurring targeting, not the cause of the 2026 breach.
  • Unattributed cyberattack against CEVA Logistics systems begins, ultimately disrupting eight European CEVA warehouses through August 1.
  • CEVA confirms the intrusion internally and begins notifying affected retail-client customers/controllers, including Bol; two systems processing Bol's distribution-center orders are identified as compromised.
  • Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is informed of the breach by affected controllers.
  • Some affected controllers begin emailing individual customers, roughly four days after CEVA's own disclosure to them — compressing each controller's independent GDPR Article 33 notification clock.
  • Valve Corporation learns of the likely compromise of Steam hardware customers' delivery data processed by CEVA.
  • Reporting (via AP/compliance analysis) confirms ten or more organizations — including ING, Bol, De Bijenkorf, Ace & Tate, AFC Ajax, Zalando, and Valve — have filed breach reports with the Dutch DPA over the same underlying CEVA incident.
  • Valve notifies affected European Steam hardware customers by email, warns of expected follow-on phishing/smishing/vishing exploiting the leaked data, and confirms passwords/payment/Steam Guard data were not exposed; TechCrunch and BleepingComputer report the wider multi-client impact.
  • The Register, SecurityWeek, and TechRadar publish additional coverage; CEVA declines to disclose attack vector, data volume, or ransom details to press.
  • Pokémon Center notifies UK and Germany PokemonCenter.com customers of the breach and cancels a number of in-flight orders, including 30th Anniversary Collection merchandise and the Ghost Chateau Cyndaquil keyring.

Sources cited for Pokémon Center Confirms Customer Data Breach via CEVA

Detection coverage for TL-2026-2054

As of 2026-08-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2054 across Splunk SPL, Microsoft KQL and Sigma, covering 14 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
14 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats