Attackers breached servers belonging to Ceva Logistics, one of the world’s largest shipping and fulfilment providers, sometime between 29 July and 1 August. The company only started notifying affected retailers this month, and the list of businesses caught up in it is a useful reminder of how invisible a fulfilment supply chain really is: the Pokémon Center’s UK and German stores, Valve’s Steam platform, and Dutch retailers Bol and De Bijenkorf have all confirmed customer data was exposed. Names, addresses, phone numbers, and email addresses are understood to be involved.

None of those brands built or ran the systems that leaked their customers’ data. They simply used a fulfilment partner that did. That’s the part worth sitting with if your business ships anything, because the same structure almost certainly sits somewhere in your own supply chain.

Why this matters even if you’ve never heard of Ceva

Most SMEs think about supply chain risk in terms of the vendors they log into directly — the accounting platform, the CRM, the email provider. Fulfilment and logistics partners rarely make that list, because you don’t “use” them the way you use software, you just hand them a parcel. But they hold your customers’ names, addresses, and contact details in exactly the same way a SaaS vendor would, often with far less visibility into their own security posture from your side.

The Ceva breach affected household names with security teams and procurement budgets most SMEs can’t match. If Valve and the Pokémon Center didn’t catch this before it happened, a smaller business checking its courier’s certifications once a year isn’t likely to catch the next one either. The response isn’t to panic-audit every supplier tomorrow — it’s to know which of them actually hold customer data, and to have a plan for when one of them gets it wrong.

Three checks worth doing this week

List who actually touches your customer data downstream. Not just your direct software vendors — your courier, your fulfilment house, any dropshipping or print-on-demand partner, any call centre or outsourced support desk. If a name on that list has never been reviewed, that’s the gap. Most small businesses can name their main software subscriptions without thinking, but struggle to name who physically handles a parcel once it leaves the building — and that blind spot is exactly where this kind of breach lives.

Ask what data your logistics partner actually holds, and for how long. A courier needs a name, an address, and enough contact detail to deliver something — it doesn’t necessarily need to retain that data indefinitely, or hold it alongside order history and payment metadata. If you’ve never asked your fulfilment provider what they keep and for how long, that’s a five-minute email worth sending this week. Retention you don’t need is retention you can’t lose.

Decide now what you’d tell customers if one of them got breached. The businesses that handled the Ceva fallout well are the ones with an existing template for “a partner of ours has had an incident, here’s what it means for you” — not the ones drafting that email for the first time under pressure. KeepSafe monitors exactly this kind of third-party exposure, so you hear about a partner breach before your customers do rather than after, giving you time to get ahead of the conversation instead of reacting to it.

Why bigger brands didn’t catch this first

It’s tempting to assume household names like Valve and the Pokémon Center have security scrutiny down to a science, and that a breach reaching them says more about Ceva than about supply chain oversight generally. That’s only half true — large brands typically do run supplier security questionnaires and contractual data-handling clauses, and this still happened to them. The lesson isn’t “do what they do, but harder.” It’s that questionnaires and contracts reduce risk, they don’t eliminate it, and the businesses that recover fastest assumed a partner breach was a matter of when, not if.

The takeaway

The Ceva breach didn’t happen to any of the businesses now dealing with it — it happened to a supplier three or four steps removed from their own systems. That’s the normal shape of supply chain risk in 2026: your exposure isn’t defined by who you trust directly, it’s defined by who they trust, and how far down that chain your customers’ data actually travels. Map your fulfilment chain this week, work out what your key partners are actually holding, and get a response plan drafted before the next one of these lands in your inbox rather than after.