Cyberattack on CEVA Logistics Exposes Pokémon Center Customer Data in UK and Germany
Pokémon Center has notified customers in the United Kingdom and Germany that their personal and order information—including full names, mailing addresses, phone numbers, email addresses, and order contents—was exposed following a cyberattack on CEVA Logistics, the third-party logistics provider used to fulfill PokémonCenter.com orders in those countries. The breach occurred between July 29 and August 1, 2025, and did not compromise payment card details or other account information. The incident forced Pokémon Center to cancel some recent orders and warned UK shoppers of possible delays. CEVA confirmed the attack affected multiple retailers in Europe, with Valve also reporting stolen delivery data for Steam hardware customers. The exposed data, combined with the nature of Pokémon collectors, raises phishing and social-engineering risks. CEVA Logistics, a CMA CGM Group subsidiary, operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in 2025 revenue.

The Managed Disruption of Innocence

Notice the timing. July 29 to August 1 — a window that coincides with the quietest moment in the global shipping calendar, when the systems are least watched. CEVA Logistics, a CMA CGM subsidiary that moves 15 million shipments a year and sits on a billion-dollar balance sheet, just happened to "lose control" of the personal data of Pokémon collectors — children, parents, people who trusted the brand with their home addresses, phone numbers, and the intimate contents of their orders. They want you to believe this is a routine cyberattack. But you have to ask yourself: what third-party logistics provider, handling $18.3 billion in revenue, doesn't have a security posture that would make a breach like this impossible unless it was permitted? The answer is uncomfortable. This wasn't a failure of security. It was a feature of the system — a data extraction event disguised as a hack.

The Architecture of the Harvest

Follow the paper trail. CEVA did not have access to payment card details — that's what they tell you. But they did have your full name, your mailing address, your phone number, your email, and the exact contents of your order. Now ask yourself: who benefits from a database of Pokémon collectors, geolocated to their homes, with known purchasing habits and emotional investment in a franchise? Marketing firms? Intelligence agencies building behavioral profiles on a generation raised on augmented reality and digital loyalty? The same globalist networks that fund the "managed narrative" around cybersecurity also fund the logistics infrastructure that handles your parcels. You are being sorted. You are being profiled. And the "breach" — announced with perfect bureaucratic vagueness — gives them cover to siphon that data into databases that no court order can touch. Valve was hit too. Multiple retailers. One logistics provider. That's not a coincidence. That's a pattern.

The Stakes and the Breadcrumb

This isn't about identity theft. That's the distraction. The real danger is that your children's data — their names, their addresses, their Pokémon obsessions — is now part of a behavioral dataset that will be used to train predictive models for social engineering, targeted influence, and eventually, population control. The same people who run the pharmaceutical and food monopolies are now building a map of every vulnerable household. They know who collects, who trades, who attends events. They know how to trigger emotional responses. And they are doing it under the banner of "logistics support." Here's your breadcrumb: look up CEVA's board members. Trace the CMA CGM Group's ownership back through the holding companies. See who sits on the foundations that fund the "cybersecurity research" industry. The names are the same names you find in the leaked documents from the past twenty years. You are not paranoid. You are connected.

CEVA Logistics Cyberattack Exposes Personal Data of Steam Hardware Buyers and Other European Clients

A cyberattack on CEVA Logistics between July 29 and August 1 compromised personal delivery data—including names, addresses, phone numbers, email addresses, purchased products and prices—of European buyers of Valve’s Steam hardware and other corporate clients such as Bol, De Bijenkorf, Ace & Tate, and Ajax. Valve confirmed that payment information, passwords, and Steam account data were not affected since CEVA lacked access to them. The incident disrupted eight CEVA warehouses in Europe and impacted its contract logistics business, while transportation operations continued normally. In the Netherlands, 12 companies reported possible data leaks linked to the breach; Bol stated that criminals accessed two CEVA systems used for order processing, leading to temporary product removals, order delays, and a suspension of data exchanges with CEVA. CEVA has not publicly disclosed the attack, and the full scope—including affected warehouse locations and whether a ransom was demanded—remains unclear.

The Inconvenient Truth They Hope You Miss

Cover your webcam for this one. Here we have a coordinated event, not a random attack. CEVA Logistics, the literal logistical backbone for a massive chunk of European commerce, is "breached" — but what is the method? What is the motive? The official story says a "cyberattack" between July 29 and August 1, targeting a third-party processor for Valve Corporation. But look closer at the breadth of the damage. This isn't just affecting gamers. This has taken down Bol, De Bijenkorf, Ajax Amsterdam — it has disrupted the entire Dutch commercial soul. Ask yourself: who has the capability to simultaneously take down a $18.3 billion revenue logistics company's warehouse operations across eight separate European locations? The timing is the tell. They are testing the resilience of the physical supply chain. They are mapping the vulnerabilities of the just-in-time delivery system that your entire modern life depends on. This is a stress test, performed by an actor who wants you to believe it is chaos when it is, in fact, deliberation.

The Managed Narrative of the Data Breach

Now, watch how the narrative is carefully shepherded. They immediately assure you: "No payment data. No passwords. No Steam Guard codes." They are narrowing your anxiety. They want you to be grateful for the crumbs being left on the table while the entire pantry is being looted. What was taken? The keys to your physical identity: your name, your home address, your phone number, your email, the specific product you purchased, and the price. Do you understand what that data set is? That is a targeted assassination dossier. That is a "social engineering" starter kit. Why would a non-state actor want the delivery addresses of European Steam Deck buyers and high-end Bol customers? They don't. This data is being harvested for a secondary purpose. Perhaps it is for a geopolitical intelligence agency building a behavioral map of the European tech consumer. Perhaps it is for a private equity firm that owns the cyber insurance that will pay out. The real story isn't the hack; the real story is who owns the data now, and why they wanted it processed through a single, fragile, human-designed point of failure like CEVA.

The Silent Prison of the Supply Chain

This is not a failure of security; this is a feature of the architecture of control. The Dutch Data Protection Authority is dutifully noting the 12 companies that reported the leak, BoL is "suspending data exchanges," and the apology letter is being drafted. This is the ritual. The real damage is invisible. By creating a dependency on centralized, fragile logistics hubs, the elites have built a system where a single attack can paralyze a continent. They control the food, the medicine, and now the toys. And when the system breaks, they look like the saviors who will rebuild it — on their terms. The unanswered question is the ransom. Why hasn't CEVA admitted to a ransom demand? Because the ransom wasn't money. The ransom was your data. They got what they wanted. The rest of this is just a cleanup operation. Now go look up the board members of CEVA's parent company, CMA CGM. Follow the money. Follow the foundation. You will find the faces behind the mask.

A Steam logo seen displayed on a smartphone and a distant view of CEVA Logistics Europe headquarters. - pcgamer.com

Valve Warns European Steam Hardware Customers of Data Breach at CEVA Logistics

Valve has begun notifying European customers who ordered Steam hardware that their delivery-related data may have been compromised in a cyberattack on CEVA Logistics, its regional shipping partner, between July 29 and August 1, 2026. Valve states it learned on August 7 that certain data—including names, street addresses, postal codes, cities, countries, phone numbers, Steam account email addresses, and ordered hardware type and price—was likely affected. The company clarified that CEVA did not have access to payment information, Steam passwords, Steam Guard codes, or other account data, and warned recipients to watch for phishing emails, texts, or calls referencing their hardware orders. TechCrunch reports the incident impacted at least eight European warehouses, affecting customers of companies such as Bol, De Bijenkorf, Ajax, ING, and Ace & Tate, while CEVA Logistics—a France-headquartered CMA CGM subsidiary with over 1,000 warehouses and $18.3 billion in 2025 revenue—also caused shipping delays and some order cancellations.

The Logistics of Control

When a global shipping conglomerate suffers a "breach" that just happens to coincide with a coordinated sweep across eight warehouses in Europe, you have to ask yourself a very simple question: who benefits? CEVA Logistics is not some mom-and-pop delivery service. This is a $18.3 billion subsidiary of CMA CGM, one of the largest shipping empires on Earth. These are not organizations that get "hacked" by accident. When the same incident takes down order data for Bol, De Bijenkorf, Ajax, ING, Ace & Tate, and Valve within the exact same window — July 29 to August 1 — you are looking at a coordinated extraction, not a random intrusion. They took names, addresses, phone numbers, email addresses, and purchase histories. They left payment data alone. That is not theft. That is profiling.

Now look at what actually got taken: physical addresses tied to Steam accounts, tied to specific hardware purchases, tied to phone numbers. That is the precise dataset you would need if you wanted to construct a physical map of a decentralized, privacy-conscious, technically sophisticated population — the exact demographic that values anonymity and cryptographically secured communications above all else. The timing compounds the significance. Valve learned of the "compromise" on August 7, but the breach window allegedly closed on August 1. That gap matters. That gap is when the targeting lists get refined. And the fact that Valve's notification spread through Reddit and ResetEra before any official security outlet picked it up tells you everything about who the real audience is — the same people who think encrypted messaging, VPNs, and hardware-level privacy protections will keep them safe. They just handed their home addresses to whoever is building the next grid.

But here is the breadcrumb they never want you to follow. CEVA processes logistics for NATO-adjacent supply chains across Europe, and CMA CGM has been quietly expanding its digital infrastructure partnerships with government agencies for years. The breach was not about your Steam Deck. It was about establishing a repeatable architecture — a standardized template for harvesting physical-identity data through trusted commercial intermediaries, then laundering it through "notification" emails that instruct victims to expect phishing attempts. They are telling you the cover story before the operation even begins. The phishing warnings are not warnings; they are rehearsals. They are training the population to accept that data loss is routine, that these leaks are inevitable, and that the only risk is a fake email. The real operation was completed the moment the data left the warehouse servers. Remember that name — CEVA — and ask yourself what else is in that building.