stadiongaming.eu

One hacked shipping company, two gaming giants: Pokémon Center joins Steam hardware in the CEVA breach

The CEVA Logistics cyberattack that exposed European Steam hardware customers has now hit Pokémon Center shoppers in the UK and Germany. Names, addresses, phone numbers and order details are in the wild - and that data is exactly what package scams feed on.

Jakov Mikelić

Wednesday, August 19, 2026

One hacked shipping company, two gaming giants: Pokémon Center joins Steam hardware in the CEVA breach

You order a Steam Deck or a plush Snorlax, and a few weeks later a logistics company you've never heard of loses your name, home address and phone number. That's the situation for a growing number of European gamers right now, and the list of victims keeps getting longer.

CEVA Logistics, one of Europe's biggest shipping companies, was hit by a cyberattack with attackers reportedly inside its systems in late July and early August. Valve was the first gaming name to sound the alarm, warning European Steam hardware customers that their data was likely compromised. Now, days later, Eurogamer reports the same breach has reached Pokémon Center - the official Pokémon merchandise store - which is notifying customers in the UK and Germany that their personal and order information may have been exposed. Some affected orders have reportedly been cancelled outright, so a hacked warehouse can literally mean no package at your door.

What leaked, according to the notifications: full names, mailing addresses, phone numbers, email addresses and details of what was ordered. What didn't: payment data, passwords and account credentials - the logistics firm never had access to those. Reports also suggest CEVA keeps order data for a limited period, roughly the last few months of shipments, which narrows the window but won't comfort anyone who bought Steam hardware this summer.

Why this matters here too

The UK and German stores might sound distant, but plenty of players in our region order Steam hardware and Pokémon merch through the German shop or via forwarding services - so "Germany" on that list is closer to home than it looks. And the leaked combination is the dangerous part: name, address, phone number and a real, recent order. That's precisely the fuel for the fake "your package is waiting, pay the customs fee" texts and emails that are already flooding phones in our region. A scammer who knows you genuinely ordered something, and roughly when, is far more convincing than one guessing blindly.

My takeaway is uncomfortable but simple: you can pick a trustworthy store, but you can't pick its logistics chain. Valve and The Pokémon Company both secured the payment side properly - and it didn't matter, because the weak link was a third party holding exactly the data needed to knock on your door. If you've ordered from either store recently, treat every delivery message with suspicion and go straight to the official tracking page instead of tapping links. The breach already happened; whether it costs you anything is now mostly about what you click next.

Image: JJBers from Willimantic, Connecticut, USA / CC BY 2.0, source: https://commons.wikimedia.org/wiki/File:Nintendo_(New_York,_New_York)_(31406686067).jpg