A single cyberattack on a third-party logistics provider has rippled across the gaming industry, and this time Pokémon collectors are feeling the pain. Just days after Valve warned European Steam hardware buyers that their personal data was stolen, Pokémon Center confirmed that UK and German customers were caught in the exact same breach. But while Valve let orders stand, Pokémon Center is cancelling affected pending orders, including highly sought-after Pokémon 30th Anniversary Cards. This is a supply-chain risk parable: two gaming giants, one shared vendor, and frustrated collectors left with cancelled orders and unanswered questions.
The CEVA Logistics Breach, Explained
The incident traces back to a cyberattack on CEVA Logistics, a massive global shipping and logistics operator and a fully-owned subsidiary of the CMA CGM Group, the world's third-largest shipping company. According to customer notification emails and industry reporting, the attack occurred between March 29 and April 1, 2026, disrupting operations at eight CEVA warehouses across Europe.
CEVA is not a small, obscure vendor. The company operates roughly 1,000 warehouses worldwide, handled approximately 15 million shipments in 2025, and generated around $18.3 billion in revenue that year. Its European footprint includes fulfilment operations for two major gaming companies: Valve's Steam hardware line, which covers Steam Deck, Steam Machine, and Steam Controller orders, and Pokémon Center's online store in the UK and Germany.
Valve began notifying affected European Steam hardware customers around April 10, 2026. Pokémon Center's notifications followed roughly a week later, landing in inboxes around April 17, 18. The overlap was not coincidence. Both companies use CEVA for European fulfilment, and both were caught in the same blast radius. At the time of publication, neither The Pokémon Company nor CEVA has issued an official public statement; all current details trace back to customer notification emails relayed through Bleeping Computer, IGN, and Eurogamer.
The video below recaps how a logistics vendor breach snowballed into simultaneous customer notifications from Valve and Pokémon Center.

What Data Was Exposed
The exposed data includes full names, mailing addresses, phone numbers, email addresses, and order details for affected customers in the UK and Germany. That is precisely the kind of information that makes phishing attacks dangerously convincing. If a scammer knows exactly which Pokémon products you ordered, a fake "order confirmation" or "shipping update" message becomes far more plausible.
The good news: payment information, passwords, and Steam Guard codes were not compromised, according to Valve and the reporting that followed. The exposed records belonged to the retailers' customers, not to CEVA's own account holders, which narrows the scope of account compromise. Still, the personal details that did leak are enough for sophisticated social engineering attempts. Both Valve and Pokémon Center have explicitly warned customers to be wary of phishing messages and fake communications referencing the breach.
Pokémon Center's Response vs. Valve's
The key difference in how the two companies responded is what has collectors up in arms. Valve's response focused on customer notification and phishing warnings. Orders were not cancelled. Pokémon Center took a different route: it began cancelling affected customers' pending orders, and IGN reports that at least some of those cancellations include Pokémon 30th Anniversary Cards.
For collectors, this stings in a way that goes beyond inconvenience. A 30th anniversary product is a once-in-a-generation release. These are items fans have been waiting years for, with finite print runs and resale values that can climb quickly. Having an order cancelled through no fault of your own, because of a logistics partner's security failure, turns what should be an exciting moment into pure disappointment.
The full scope of the cancellations remains unclear. Some reports describe "some orders" or "a batch of pending orders," while others describe a larger wave of cancellations. The Pokémon Company has not publicly disclosed exactly how many orders are affected or how it decided which ones to cancel. What is clear is that affected customers are being notified directly, and the 30th Anniversary Cards are firmly in the cancellation zone.

The Blast Radius Goes Beyond Steam and Pokémon
Pokémon Center and Valve were not the only casualties of the CEVA breach. Dutch retailers Bol and De Bijenkorf also warned customers that their personal data may have been leaked and that orders could be delayed or cancelled. This widens the story beyond gaming into general retail, and it underscores a broader supply-chain vulnerability: one compromised logistics vendor can expose customer data across multiple industries simultaneously.
For the gaming audience, the lesson is blunt. Even a well-known brand like Pokémon or Valve is only as secure as its weakest third-party partner. These companies do not run their own European warehouses and delivery networks. They outsource to specialists like CEVA, and when that specialist suffers a breach, the brands take the reputational hit while customers deal with the consequences. The "single point of failure" concept is on full display here: a shared vendor means a single attack can trigger parallel PR nightmares and customer-impact decisions at multiple companies, all at once.
What Affected Customers Should Do Now
If you received a notification from Pokémon Center or Valve about the CEVA breach, the practical steps are straightforward. Be highly suspicious of emails, text messages, or phone calls that reference your order details. Do not click links in unsolicited messages. Log in directly to the official Pokémon Center or Steam websites by typing the address yourself, and check your order status from there. If you are worried about your credentials, changing your password on the official sites is a reasonable precaution, even though password data was not part of this breach.
Payment data was not compromised, but the exposed personal details can still be leveraged for social engineering. If someone calls claiming to be from your bank or a gaming retailer and knows your name, address, and recent order history, that is a red flag, not a demonstration of legitimacy. Hang up and contact the official support line directly.
There are still major unanswered questions. What is the full scope of cancelled orders? Will collectors receive refunds automatically, or will they need to fight for them? Will there be priority access to restocks for affected customers, or are the anniversary products simply gone? And will The Pokémon Company or CEVA issue an official public statement with more details? Until then, affected collectors should check official communication channels rather than relying on third-party summaries, and treat any dramatic claims with healthy skepticism. Unverified rumors, such as the suggestion that 89 million Steam records are being sold in connection with this incident, conflict with Valve's description of the breach and have not been confirmed by reputable sources. They should be ignored until substantiated.
A Single Point of Failure
The CEVA Logistics breach is a stark reminder that data security and order fulfilment can be derailed by a single third-party vendor. For Pokémon fans, the pain is tangible: 30th Anniversary Card orders cancelled through no fault of their own, plus personal data exposed in the process. Valve and Pokémon Center have both told customers to stay alert for follow-on scams, but the bigger takeaway is structural. The gaming industry's reliance on shared logistics partners creates risks that players and brands cannot fully control. As details continue to emerge, affected customers deserve transparency, and in Pokémon's case, a chance to secure the anniversary products they lost.






Comments
Join the Conversation
Share your thoughts, ask questions, and connect with other community members.
No comments yet
Be the first to share your thoughts!