Tendvane

← All articles

AccountsAugust 18, 2026

The shop wasn't hacked. The company that shipped your parcel was.

Pokemon Center started writing to customers in the UK and Germany on Monday to say their details had been taken, and cancelled some orders outright. Nobody broke into Pokemon Center. The breach was at CEVA Logistics, the contract shipping firm handling its European deliveries, and the intrusion happened three weeks ago - between 29 July and 1 August.

CEVA is enormous: part of the CMA CGM shipping group, more than a thousand warehouses worldwide. Eight of its European sites were disrupted. Customer notices have been trickling out ever since, one retailer at a time. Valve wrote to Steam hardware buyers earlier this month; TechCrunch counted the Dutch retailer Bol, the department store de Bijenkorf, the bank ING, football club Ajax and eyewear brand Ace & Tate among those caught up in it, with ten organisations filing breach reports to Dutch regulators.

No card numbers were taken - CEVA never had them. What it did have is everything on the shipping label: your full name, delivery address, phone number, email, and what was actually in the box. Valve noted that CEVA holds shipping and delivery information for 90 days after an order.

Think about what someone can write with that. Not "we couldn't deliver your parcel, pay 1.99." Something that names the item you ordered, quotes your address correctly, and arrives while you're genuinely waiting on a delivery. That's a different quality of bait altogether. For the next month or two, treat any delivery message as a prompt rather than a link: go to the retailer's own site or app and look the order up there.

Tendvane's Privacy & accounts check shows which of your email addresses have already surfaced in known breaches, which is a decent way to gauge how much of you is circulating before the convincing message shows up.

Sources

Download Tendvane