A cyberattack on CEVA Logistics between 29 July and 1 August 2026 is producing downstream disclosures weeks later, one client at a time. Pokémon Center confirmed customers in the United Kingdom and Germany were affected — full names, postal addresses, email addresses, phone numbers and order histories, though not payment or login details — and cancelled or delayed orders, including pre-orders for a trading-card expansion. Reporting connects the same incident to Valve, ING, Ajax, bol, De Bijenkorf and Ace & Tate.
No aggregate count of affected people exists in the material reviewed, and each affected brand is disclosing — or not — on its own schedule.
One Warehouse, Many Letters
CEVA is a fulfilment layer: it stores, picks and ships for retailers that keep their own brands on the box. The structure filed at 25-0801 for healthcare administrators applies unchanged — the organisation with the customer relationship and the organisation holding the customer data are different organisations, and the second one had the incident. The affected population is defined by which retailers used which warehouse, a fact no customer could know.
Some People Were Notified By A Missing Parcel
Cancelled orders reached some customers before, or instead of, any breach notice. The corpus recorded the same arrival channel at 25-0606, where grocers learned their distributor had been attacked by observing that nothing arrived. Availability told the story first, and for the pre-order customers the cancellation is the injury they will actually remember — the data exposure is abstract, the missing delivery is not.
The Disclosure Fragments With The Supply Chain
One intrusion at one provider is reaching the public as a series of unconnected brand-level stories, spread over weeks, in different countries and languages. Nothing obliges anyone to publish the aggregate, so the incident’s true size will exist only as this scattered list — a worked example of why supplier events are systematically undercounted in every breach statistic, including the ones built from files like this.
Compiled from client notifications as reported and contemporaneous coverage, listed below. The intrusion window is as reported; CEVA had not published a detailed account in the material reviewed. The client list beyond Pokémon Center reflects reporting, not confirmations from each brand. Graded medium. Corrections: corrections@forensicpost.com.