CEVA data breach: after Valve, the Pokémon Center cancels orders
Credit: Crédit : Valve

CEVA data breach: after Valve, the Pokémon Center cancels orders

Fabian Fabian Lainé
Follow us on

In brief

The cyberattack on CEVA Logistics, the logistics provider for Valve and The Pokémon Company in Europe, exposed the personal data of thousands of buyers between late July and early August. While Valve delivered its orders and notified its customers, The Pokémon Company chose to mass-cancel preorders for the 30th anniversary cards without any public explanation.

One single cyberattack, two gaming giants affected, and European buyers in both cases. After Valve in early August, it's now The Pokémon Company mass-cancelling pre-orders for 30th anniversary cards placed on the Pokémon Center, warning its customers of a data theft.

The weak link is called CEVA

The common thread between the two cases is CEVA Logistics, the provider that ships both brands' packages in Europe. The intrusion reportedly took place between July 29 and August 1; Valve says it was informed on August 7 and wrote to its customers that same day. The carrier claims the damage is limited to eight of its European warehouses.

The data involved is the same on both sides: first and last name, full postal address, phone number, account email address, and details of the ordered items along with their price. No login credentials, passwords, Steam Guard codes, or payment methods are involved — CEVA never had access to them.

What this means for you

The difference in handling raises questions. Valve delivered its orders and simply issued a warning; The Pokémon Company is outright cancelling, without explaining why, on one of the most sought-after sets of the year. The publisher has not responded to press inquiries and has not issued any public statement.

The immediate risk isn't account hacking but phishing: a message that cites your exact order and address is far more convincing than a generic email. If you bought a Steam Deck, a Steam Machine, or placed an order on the Pokémon Center this summer, treat any

Share this article

How do you rate the difference in handling between Valve and The Pokémon Company regarding this leak?

Frequently asked questions

What exact data was stolen in the CEVA attack?
The hackers have access to your first and last name, full postal address, phone number, account email, and your order details including prices. No password, Steam Guard credentials, or payment method was compromised, since CEVA never had access to them.
Why is The Pokémon Company cancelling orders while Valve delivered them?
The publisher has given no explanation and has not responded to press inquiries. The two strategies differ radically: Valve chose transparency and continuity, while The Pokémon Company opted for cancellation without any public justification.
What's the real risk for victims of this data leak?
Mass phishing represents the immediate danger. With your exact address and order details in hand, scammers can send fake delivery messages that are far more convincing than a generic email.
How can I protect myself if I ordered from Valve or the Pokémon Center this summer?
Treat any delivery follow-up message with suspicion. Check directly with official websites rather than clicking on links received by email or text message. Two-factor authentication also strengthens your security.

Key takeaways

  • CEVA Logistics, a shared provider for Valve and The Pokémon Company, suffered an intrusion affecting eight European warehouses
  • The compromised data includes name, address, phone number and email, but no banking details or passwords
  • Valve delivered its orders and quickly notified its customers on August 7, while The Pokémon Company is cancelling orders with no public communication
  • The real danger isn't account theft but phishing that uses your order data to impersonate a delivery

Comments

No comments yet. Be the first to react!

Leave a comment

Latest articles