CEVA Logistics
Steam customers, Pokémon collectors and bank clients were all breached by the same incident, at a company none of them had heard of.
What happened?
CEVA Logistics, one of the world's largest shipping and logistics operators, was breached in an attack affecting at least eight European warehouses used to ship goods across the continent. Reporting on August 10, 2026 described the incident rippling outward across banks, retailers, and gaming customers.
Companies that rely on CEVA for fulfilment have since confirmed their own customers were affected. Pokémon Center disclosed exposure covering UK and German customers. Valve confirmed Steam hardware customers were affected.
What data was actually inside?
Per the downstream disclosures: full names, mailing addresses, phone numbers, email addresses, and order and product details.
Fulfilment data is unglamorous and unusually complete. To deliver a parcel you need the recipient's legal name, their residential address, a working phone number for the courier, and a description of exactly what is in the box. No field is optional and no field is speculative — every one has been validated by the act of successful delivery.
That is a verified household identity record with a purchase history attached.
Who gets hurt and how?
Consumers across multiple countries who bought from brands that outsource fulfilment. Most will learn of the incident from a brand they recognise, about a company they do not.
The order detail is the element people underrate. Knowing what someone bought, when it shipped, and where they live supports a delivery-problem phishing message that is convincing because every detail in it is correct. Courier-impersonation fraud is already among the highest-conversion phishing categories, and this dataset removes the guesswork.
There is a physical dimension as well. A list of residential addresses paired with high-value electronics purchases and delivery dates describes which homes recently received expensive hardware.
What did they think they were doing right?
The brands did the thing modern data protection asks of them. They minimised. Payment data stays in the payment processor. Account credentials stay in the platform. Only the fields strictly necessary for delivery go to the fulfilment partner, which is exactly what purpose limitation requires.
Necessary for delivery turns out to be a rich set. Minimisation reduced what the logistics provider received; it did not make what remained low risk, because a name, home address, phone number, and itemised order is a complete profile of a household regardless of how carefully it was scoped.
What did they not know about their own data?
Most organisations can produce an inventory of the data they collect. Very few can produce an inventory of the data they transmit — which partner receives which fields, on what schedule, retained for how long, and covering which historical period.
Retention is where this becomes acute. A brand's own retention policy governs its own systems. The fulfilment partner's retention is governed by the partner's practice, which is typically to keep shipment records for years for claims and customs purposes. So a customer who ordered once in 2021 and deleted their account may still be in the logistics provider's archive, and the brand cannot see that.
When the partner is breached, each brand must answer which of its customers were in the affected window using records held by someone else.
If your business runs on databases, you probably have similar records—customer data, credentials, financial information. Do you know what's actually in yours?
What does attribution look like the morning after?
Under GDPR the brands are controllers and the logistics provider is a processor, which places the notification obligation on the brands. The processor must inform the controller without undue delay; the controller then has 72 hours from awareness to notify the supervisory authority. The controller's clock therefore depends on information it does not hold.
Each affected brand runs its own analysis, files with its own lead authority, and communicates to its own customers, so a single incident at one supplier becomes a dozen parallel regulatory processes across multiple member states. UK customers add UK GDPR and the ICO. The brands also absorb the reputational cost, because the notification letter carries their name and the customer has no relationship with CEVA.
What would have changed the outcome?
An outbound data map: which fields go to which partner, retained how long, covering which customers — maintained by the brand, not the supplier.
You inventoried the data you collect. The harder and more useful artifact is an inventory of the data you send. Every fulfilment partner, payment processor, support platform, and marketing tool holds a slice of your customer records under retention terms you did not set and cannot observe. When one of them is breached, the notification obligation returns to you and the facts do not. Compare our analysis of the Sakura Internet breach, which is the same dependency viewed from the provider's side.
CEVA Logistics found out the hard way.
Your team could spend the next 6 months rebuilding systems, notifying customers, and answering legal questions. Or you could spend 24 hours finding out what's actually at risk.