Desk live·
ForensicPost
Breaches/Logistics/File 26-0822

CEVA Logistics Breach Reaches Pokémon Center, Valve, ING and a Widening Retail List

A four-day intrusion at the logistics giant in late July is surfacing one client disclosure at a time — names, addresses and order histories, plus cancelled orders. Some customers learned of the breach when their parcels stopped.

Constructed geometry · not a chart of case data
JurisdictionFranceMarseillethe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetCEVA Logistics client customers
ActorUnattributed
S. Rosler11 min readConfidence: medium3 sources reviewed

A cyberattack on CEVA Logistics between 29 July and 1 August 2026 is producing downstream disclosures weeks later, one client at a time. Pokémon Center confirmed customers in the United Kingdom and Germany were affected — full names, postal addresses, email addresses, phone numbers and order histories, though not payment or login details — and cancelled or delayed orders, including pre-orders for a trading-card expansion. Reporting connects the same incident to Valve, ING, Ajax, bol, De Bijenkorf and Ace & Tate.

No aggregate count of affected people exists in the material reviewed, and each affected brand is disclosing — or not — on its own schedule.

One Warehouse, Many Letters

CEVA is a fulfilment layer: it stores, picks and ships for retailers that keep their own brands on the box. The structure filed at 25-0801 for healthcare administrators applies unchanged — the organisation with the customer relationship and the organisation holding the customer data are different organisations, and the second one had the incident. The affected population is defined by which retailers used which warehouse, a fact no customer could know.

Some People Were Notified By A Missing Parcel

Cancelled orders reached some customers before, or instead of, any breach notice. The corpus recorded the same arrival channel at 25-0606, where grocers learned their distributor had been attacked by observing that nothing arrived. Availability told the story first, and for the pre-order customers the cancellation is the injury they will actually remember — the data exposure is abstract, the missing delivery is not.

The Disclosure Fragments With The Supply Chain

One intrusion at one provider is reaching the public as a series of unconnected brand-level stories, spread over weeks, in different countries and languages. Nothing obliges anyone to publish the aggregate, so the incident’s true size will exist only as this scattered list — a worked example of why supplier events are systematically undercounted in every breach statistic, including the ones built from files like this.

How we reported this

Compiled from client notifications as reported and contemporaneous coverage, listed below. The intrusion window is as reported; CEVA had not published a detailed account in the material reviewed. The client list beyond Pokémon Center reflects reporting, not confirmations from each brand. Graded medium. Corrections: corrections@forensicpost.com.

Sources
  1. Pokémon Center data breach exposes customer info, cancels some ordersBleepingComputer
  2. Gotta catch ‘em all: Pokémon Center caught in CEVA Logistics breachCybernews
  3. Pokémon Center Customers Hit By Same Data Breach As ValveKotaku
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary