A cyberattack on CEVA Logistics has compromised customer order information across multiple brands, prompting warnings over fraudulent messages and highlighting risks within supply chain security.
A cyberattack on CEVA Logistics has left European customers of Pokémon Center and Valve facing delays, cancellations and a fresh warning about fraudulent messages, after order-related information may have been exposed in a breach at the logistics provider. The incident highlights how a compromise at a third-party supplier can spill across multiple brands without either retailer being directly breached.
According to reports from Tom’s Hardware, IT Pro and PC Gamer, the attack hit CEVA systems between 29 July and 1 August 2026 and affected at least eight European warehouse sites. Valve said it learned of the theft on 7 August and began notifying customers whose Steam hardware purchases may have been involved. CEVA has reportedly isolated affected systems and brought in external investigators, while also informing data protection authorities.
The information at risk is mainly logistical rather than financial. Valve said names, postal addresses, phone numbers, email addresses and purchase details may have been accessed for customers who bought hardware such as the Steam Deck, Steam Machine or Steam Controller. The company said passwords, Steam Guard codes and payment details were not part of the data held by the shipping partner.
That distinction matters, but it does not remove the risk. Security specialists note that even partial order data can be enough for highly convincing phishing attempts. Valve has warned affected customers to expect fake emails, text messages or phone calls claiming to come from the company or delivery firms, and said users should type official support addresses into their browsers rather than follow links in unsolicited messages.
The breach also appears to have had wider operational consequences. TechRadar reported that CEVA’s disruption affected other European customers too, with Dutch retailers Bol and De Bijenkorf among those reporting delays or possible exposure of order data. Other companies named in coverage included ING Bank, Levi Strauss, Ajax Football Club and Ace & Tate, underscoring the breadth of the logistics firm’s reach.
For consumers, the immediate practical advice is straightforward: treat any message about a missing parcel, extra fee or account verification with caution, and check the order status only through the retailer’s own website or app. For companies, the episode is another reminder that supplier security is part of their own security posture. In a connected logistics network, a weakness at one provider can rapidly become a customer-facing incident for many organisations at once.
Disclaimer: This content is intended for informational purposes only. Readers are advised to exercise their own judgement, conduct due diligence, or consult a qualified expert before acting on any information provided.





