# Pokémon Center Confirms Customer Data Breach via CEVA Logistics Supply-Chain Compromise

> Pokémon Center is notifying UK and Germany customers of a data breach after third-party shipping vendor CEVA Logistics suffered a cyberattack (~July 29 - August 1, 2026) that compromised systems CEVA uses to process delivery information for retail clients. The same intrusion rippled into at least nine other CEVA clients across banking, retail, sport, eyewear, and gaming, and disrupted eight European CEVA warehouses.

- **Published:** 2026-08-18T00:00:00Z
- **Last reviewed:** 2026-08-18T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2054
- **ID:** TL-2026-2054
- **Severity:** HIGH
- **Category:** DATA_BREACH
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 14 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Between roughly July 29 and August 1, 2026, an unattributed threat actor breached systems operated by CEVA Logistics, the France-headquartered contract-logistics arm of shipping group CMA CGM (2025 revenue ~$18.3B, over 1,000 warehouses worldwide). CEVA confirmed the intrusion disrupted at least eight of its European warehouses and that two of the compromised systems processed order/delivery data for retail client Bol's distribution center; CEVA stated the operational impact was contained to those eight sites and that no other CEVA systems globally were affected. CEVA has not publicly disclosed the initial-access vector, the volume of records taken, whether a ransom was demanded, or attributed the intrusion to a specific actor; the company did not respond to press inquiries from The Register, SecurityWeek, or TechCrunch about attack methodology.

Because CEVA operates as a shared data processor for many unrelated retail, financial, sporting, and gaming brands' European order-fulfillment pipelines, the single intrusion cascaded into a multi-tenant breach: Dutch e-commerce giant Bol, luxury department store De Bijenkorf, eyewear retailer Ace & Tate, football club AFC Ajax, bank ING, e-commerce firm Zalando, and Valve Corporation (Steam hardware shipments — Steam Machines, Steam Controllers, Steam Deck units) all confirmed exposure of customer records tied to CEVA-processed orders. Ten or more organizations reported the breach to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) as controllers under GDPR, with CEVA acting as their shared processor. Valve stated it learned of the likely compromise on August 7, 2026 and notified customers August 10; it retains CEVA-processed delivery data for 90 days post-order, defining its exposure window. Pokémon Center — which uses CEVA to fulfill PokemonCenter.com orders in the UK and Germany — began notifying affected customers August 18, 2026, and canceled a number of in-flight orders (including 30th Anniversary Collection items and the Ghost Chateau Cyndaquil keyring) as a result, without a public explanation for why cancellation rather than delay was necessary.

Exposed data across the affected organizations consistently comprises full names, mailing addresses/postcodes, phone numbers, email addresses, order numbers, shipment tracking information, order contents/pricing details, and — for at least one retail client — gift-card message text attached to orders; no payment card data, bank account numbers, Steam credentials/Steam Guard codes, or passwords were exposed, as CEVA's systems never had access to that data. CEVA has stated it isolated the affected systems and engaged external investigators as part of its response, and that transportation operations continued uninterrupted throughout. A compliance analysis of the incident (ComplianceHub) reconstructs a notification chain in which CEVA disclosed to customers/controllers on August 1, the Dutch DPA was informed by August 3, some controllers emailed data subjects by August 5 (a four-day gap from CEVA's own disclosure), and Valve independently discovered the compromise on August 7 — illustrating how a processor-side breach compresses each controller's independent 72-hour GDPR Article 33 notification clock, with additional 24-hour/72-hour NIS2 reporting obligations attaching to CEVA itself as a high-criticality transport-sector entity, and DORA obligations attaching to affected financial entities like ING.

Valve's customer notification explicitly warned that the leaked name/address/order data will make follow-on impersonation fraud unusually convincing: affected customers should expect phishing by email, SMS, and phone that impersonates Steam, Valve, or delivery couriers, quotes the victim's real address back to them to appear legitimate, and asks them to confirm a delivery, pay a small fake customs/redelivery fee, or sign in somewhere to "verify" an order. Valve stressed customers do not need to change Steam passwords or account settings, since account credentials were never part of the exposure. Multiple outlets (Malwarebytes, RespawnFirst, FinalBoss) independently amplified this warning; no outlet has yet reported an observed, in-the-wild phishing campaign specifically tied to this data, only the anticipated risk flagged by Valve.

Context: CEVA Logistics was previously compromised in a distinct, unrelated September 2025 incident claimed by the extortion group 'Coinbase Cartel,' which exploited an exposed FortiOS SSL-VPN credential set (CVE-2022-40684 / FortiBleed) to access CEVA employee and third-party credentials. That 2025 incident is a separate confirmed compromise of the same recidivist vendor and is cited here only as precedent for CEVA's recurring targeting; no source ties CVE-2022-40684 or Coinbase Cartel to the July-August 2026 breach, and this record does not attribute the current intrusion to that vector or actor.

## MITRE ATT&CK

- T1199 Trusted Relationship
- T1213 Data from Information Repositories
- T1589 Gather Victim Identity Information
- T1566 Phishing
- T1566.002 Spearphishing Link
- T1660 Phishing
- T1598.004 Spearphishing Voice
- T1204.001 Malicious Link
- T1684.001 Impersonation
- T1657 Financial Theft

## Sources

- [Pokémon Center Confirms Data Breach](https://cybersecuritynews.com/pokemon-center-confirms-data-breach/)
- [Pokémon Center data breach exposes customer info, cancels some orders](https://www.bleepingcomputer.com/news/security/pokemon-center-data-breach-exposes-customer-info-cancels-some-orders/)
- [Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe](https://therecord.media/ceva-logistics-cyberattack-bol-steam-debijenkorf-ace-tate)
- [Cyberattack on logistics giant CEVA delivers customer data into the wrong hands](https://www.theregister.com/cyber-crime/2026/08/11/cyberattack-on-logistics-giant-ceva-delivers-customer-data-into-the-wrong-hands/5286229)
- [A data breach at shipping giant Ceva Logistics is rippling across banks, retailers, Steam gamers, and beyond](https://techcrunch.com/2026/08/10/a-data-breach-at-shipping-giant-ceva-logistics-is-rippling-across-banks-retailers-steam-gamers-and-beyond/)
- [Valve notifies Steam hardware customers of a data breach](https://www.bleepingcomputer.com/news/security/valve-notifies-steam-hardware-customers-of-a-data-breach/)
- [Ceva Logistics Operations Disrupted by Cyberattack](https://www.securityweek.com/ceva-logistics-operations-disrupted-by-cyberattack/)
- [Ceva Logistics: One Processor, Ten Controllers, and a Notification Chain That Took Five Days](https://compliancehub.wiki/ceva-logistics-breach-ten-controllers-one-processor-gdpr-nis2-2026/)
- [Valve warns Steam hardware buyers: Expect fake delivery scams](https://www.malwarebytes.com/blog/data-breaches/2026/08/valve-warns-steam-hardware-buyers-expect-fake-delivery-scams)
- [The CEVA Logistics data breach is having major knock-on effects across Europe - here's what we know](https://www.techradar.com/pro/security/the-ceva-logistics-data-breach-is-having-major-knock-on-effects-across-europe-heres-what-we-know)
- [Cyberattack on Steam hardware shipper leaks names, addresses, and order data](https://www.helpnetsecurity.com/2026/08/10/valve-data-breach-ceva-logistics-steam-hardware/)
- [Victim: Ceva Logistics @ coinbasecartel](https://www.ransomware.live/id/Q2V2YSBMb2dpc3RpY3NAY29pbmJhc2VjYXJ0ZWw)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2054
