Customers across Europe are facing delivery cancellations and data exposure following a security incident at third-party logistics vendor CEVA Logistics. The CEVA Logistics cyberattack compromised systems handling order fulfillment, directly leading to the Pokémon Center data breach for online shoppers in the United Kingdom and Germany, as well as impacting Steam hardware customers ordering from Valve.
Scope of Exfiltrated Data and Affected Systems
CEVA Logistics, a subsidiary of the CMA CGM Group operating over 1,000 warehouses globally, detected unauthorized access to its European server infrastructure occurring between July 29 and August 1. Because e-commerce platforms share customer shipping details with third-party logistics (3PL) partners to facilitate order dispatch, attackers accessing CEVA’s network were able to extract personal identifiable information (PII) belonging to recent buyers.
For Pokémon Center customers who placed orders on PokemonCenter.com in the UK and Germany, compromised records include:
- Full customer names
- Delivery and mailing addresses
- Telephone numbers
- Email addresses
- Specific order contents and product details
Valve issued similar breach notifications to European Steam hardware purchasers whose delivery information was stored on CEVA’s network. In both cases, payment card details were not compromised, as CEVA does not maintain access to financial processing systems or full credit card records.
Warehouse Disruption and Order Cancellations
Beyond data exfiltration, the intrusion severely impaired CEVA’s physical fulfillment capabilities. The attack disrupted operations across eight European warehouses, causing regional dispatch delays and forcing Pokémon Center to cancel a subset of pending orders outright.
Impacted shoppers reported receiving unexpected cancellation notices for various items, ranging from high-demand 30th-anniversary collection releases to individual items like the Ghost Chateau Cyndaquil keyring. While third-party security incidents frequently cause temporary shipping backlogs, outright order cancellations typically indicate that warehouse management systems (WMS), picking control software, or order-state mapping databases were either encrypted, isolated for forensic analysis, or rendered untrusted during containment efforts.
Supply Chain Risk and Data Retention Windows
Third-party logistics providers represent a soft targets in e-commerce supply chains. Vendors like CEVA sit at the intersection of inventory management, order routing, and customer location data. By targeting a single 3PL partner, threat actors can gather high-value operational data across multiple client brands simultaneously, multiplying the blast radius of a single access vector.
The incident also highlights the risks associated with third-party data retention. Breach communications sent by Valve noted that CEVA retains delivery-related information for up to 90 days after an order is processed. While retaining delivery metadata for 30 to 90 days is standard practice to accommodate tracking inquiries, package claims, and return processing, holding customer PII on fulfillment networks expands the attack surface. Every day customer records linger in a 3PL environment increases exposure if that vendor suffers a credential compromise or network breach.
Downstream Phishing and Mitigation Guidance
While financial credentials remain secure, exfiltrated order records provide threat actors with precision tools for social engineering. Attackers frequently cross-reference stolen full names, phone numbers, and physical addresses to conduct highly convincing spear-phishing and smishing (SMS phishing) campaigns. Customers who recently placed an order—or had an order canceled—are particularly susceptible to fake parcel-tracking alerts, “failed delivery fee” scams, or refund requests that cite exact product names and purchase details.
Guidance for Impacted Customers
- Treat delivery communications with caution: Watch for unprompted SMS or email messages demanding payment for re-delivery, address verification, or customs fees.
- Verify order status directly: Always navigate directly to the merchant portal (PokemonCenter.com or Steam) rather than clicking links embedded in text messages or automated emails.
- Report suspicious communications: Mark unrecognized messages claiming to be from CEVA Logistics or delivery couriers as spam.
Guidance for E-Commerce Organizations
- Enforce automated data purge policies: Restrict 3PL vendors from retaining customer PII longer than necessary for fulfillment and return windows, strictly enforcing deletion schedules via automated API policies.
- Isolate vendor integration endpoints: Implement strict boundary controls between primary e-commerce backend databases and 3PL fulfillment APIs to prevent vendor-side disruptions from corrupting core inventory or order tracking workflows.
Related content
18% of Data Center Physical Infrastructure Assets Sit One Hop From Public Internet
Security NewsLidl Online Shop Customers Affected by Third-Party Data Breach
AdvisoryCisco FMC Authentication Bypass (CVE-2026-20079) Grants Root Access
AdvisoryCisco FMC Hard-Coded Password Flaw (CVE-2026-20316): Attack Paths & Triage
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call