Comserv Connect
← Back to Blog
Cybersecurity

The Layer Below Your Vendor List

By Comserv Connect TeamReviewed by Chris Ferrera

If a Pokemon Center order was cancelled on you this month, the email blamed an unforeseen fulfilment issue.

It was a cyberattack. Not on Pokemon.

Pokemon Center is the official Pokemon online store. In the UK and Germany it does not pack and ship its own orders. A contract logistics firm called CEVA Logistics does that, and CEVA is one of the largest logistics companies in the world. By CEVA's own account the intrusion most likely began on 29 July. It disrupted at least eight of its warehouses across Europe, and reporting has tied the same incident to disruption reaching other brands, including Valve, the company behind Steam.

CEVA told Pokemon Center. Pokemon Center then notified customers in the UK and Germany that their full names, mailing addresses, phone numbers, email addresses and the contents of their PokemonCenter.com orders had been exposed. No payment card details, for the straightforward reason that CEVA never held any.

Nobody has claimed the attack. The entry point has not been confirmed publicly. That matters, and we will come back to it.

Here is the part worth sitting with. Every one of those customers chose Pokemon. Not one of them chose CEVA. Most had never heard the name until they read the notification, and the first many knew of it was an order that quietly did not arrive.

It Goes Deeper Than One Layer

Five days before that notification went out, a separate company had a version of the same week.

Trezor, which makes hardware wallets, disclosed on 13 August that 13,689 of its customers had personal details exposed, 11,742 of them fully and 1,947 partially. Trezor was not breached. Its fulfilment provider, ShipMonk, was. And ShipMonk was reached through a flaw in Metabase, a reporting tool ShipMonk runs internally to look at its own data.

Trezor says the contents of the parcels were not exposed. Pokemon's customers were less lucky there. Their order contents were part of it.

Count that chain. The customer chose Trezor. Trezor chose ShipMonk. ShipMonk chose Metabase. The break-in happened at the far end of a chain the customer could not see and had no say in.

These are two separate incidents with two different causes, and it is worth being precise about that rather than bundling them into one scary trend. The Trezor chain traces to a specific software flaw. The CEVA attack has no confirmed entry point and nobody has claimed it. What they share is not a cause. It is a shape.

Why the Usual Advice Does Not Cover This

The standard guidance is to know your vendors. It is good advice, and we have given it ourselves. When we wrote about the charity donor databases taken from a CRM company, the one concrete thing we asked people to do was write down every outside company holding a customer or supporter record for them.

We stand by that. It also would not have helped here.

Pokemon Center could name CEVA. Trezor could name ShipMonk. Both were deliberate choices, under contract, exactly the sort of vendor that advice is about. The break was one layer further down, and that layer does not appear on any list you would naturally build.

Your contracts cover the companies you chose. They do not cover the companies your companies chose. That is the gap, and almost nobody talks about it.

Why a Reporting Tool Is the Worst Place for This to Happen

Worth a moment on the Trezor chain specifically, because of what sat at the end of it.

Metabase is business intelligence software. Its entire job is to connect to all of your databases so someone can ask questions across them. Which means administrative access to it is administrative access to everything it touches, at once.

Most software holds one kind of data. A reporting tool holds a route to all of it. If you take one technical thing from this piece, it is that the tools which sit across everything deserve more attention than the tools that sit beside one thing.

What You Can Actually Find Out

This layer is more visible than most people expect.

Under GDPR Article 28, a company that processes personal data on your behalf has to disclose who it passes that data to. In practice most serious vendors publish a sub-processor list, usually with a commitment to give notice, often 30 days, before adding anyone new.

You can read those. Search the vendor's name and the word subprocessors. It is a public page, it costs nothing, and it names the layer you could not otherwise see. If you are on Microsoft 365, there is now a setting in your own admin centre called "AI providers operating as Microsoft subprocessors," which is the same idea applied to the AI systems handling your data.

The second source is a vendor's SOC 2 report, which has a section on subservice organisations naming what they depend on.

Neither is perfect. The lists change several times a year and vendors rarely announce it. But it is the difference between not knowing and being able to know.

Can You Get Told When It Happens?

Partly, and it is worth being honest about how partly.

Ransomware groups publish their victims, often before the victim says anything publicly, and several free trackers aggregate those postings. If a supplier appears there, that is usually the earliest signal available.

Public companies in the US have to disclose material cybersecurity incidents in an SEC filing within four business days.

Both have real gaps. Leak sites only see the crews that publish, so a quiet intrusion or a straight data theft may never appear there. Note that nobody has claimed the CEVA attack, which is exactly the case where that method tells you nothing. SEC filings only cover public companies, and most suppliers a small business relies on are private.

So partial coverage, honestly described. Which is still better than the nothing most businesses have today.

The One Question Worth Asking

You are not going to audit your suppliers' suppliers. Nobody at a twenty person company has time for that, and we are not going to pretend otherwise.

But there is one question worth putting to whichever vendor holds the most customer data for you:

When one of your suppliers is breached, how and when do we find out?

That is a phone call, not a project. And the answer tells you almost everything. A vendor who has thought about this has a process and will describe it. A vendor who has not will change the subject.

The Part You Cannot Avoid

Prevention is genuinely not on the table here. Pokemon did not do anything wrong. Neither did their customers, or Trezor's.

What is on the table is speed. When something like this reaches you, the only thing that actually matters is how quickly you can tell your own customers what happened and what it means for them. Blame is beside the point, because they are going to call you regardless of whose fault it was.

That is the part worth being ready for. If you want help working out which of your vendors holds the most, and what you would say on the day one of them has a bad week, book a free 30-minute strategy session.

Sources

  1. BleepingComputer: Pokemon Center data breach exposes customer info, cancels some orders
  2. Forbes: Pokemon Center customer data exposed as third-party breach confirmed
  3. TechCrunch: a data breach at shipping giant CEVA Logistics is rippling across banks, retailers and Steam gamers
  4. Kotaku: Pokemon Center hack, cancelled orders and the CEVA link
  5. Trezor: recent customer data exposed in shipping provider incident
  6. BleepingComputer: Trezor discloses data breach affecting nearly 14,000 customers
  7. Microsoft Learn: AI providers operating as Microsoft subprocessors

Want the Checklist We Actually Use?

The same checks we run for the businesses we protect, in plain language. Free PDF, no vendor pitch.