08/26/2026
If a Pokémon Center order was cancelled on you this month, the email blamed an unforeseen fulfilment issue.
It was a cyberattack. Not on Pokémon.
In the UK and Germany, Pokémon Center does not pack and ship its own orders. A logistics firm called CEVA Logistics does. CEVA was attacked, and customers were then told their names, addresses, phone numbers, emails and the contents of their orders had been exposed.
Every one of those customers chose Pokémon. Not one of them chose CEVA. Most had never heard the name until they read the notification.
Days earlier, Trezor said 13,689 of its customers had details exposed. Trezor was not breached either. Its shipping provider was.
The usual advice is to know your vendors. Good advice, and it would not have helped here. Both companies could name their vendor. The break was one layer down. Your contracts cover the companies you chose, not the companies your companies chose.
You are not going to audit your suppliers' suppliers, and we are not going to pretend otherwise.
But there is one question worth asking whichever vendor holds the most customer data for you. When one of your suppliers is breached, how and when do we find out?
That is a phone call, not a project. A vendor who has thought about it will describe their process. A vendor who has not will change the subject.
The full version, including what you can look up for free today: https://www.comservconnect.com/blog/the-layer-below-your-vendor-list