Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics.
Data Breach Details
While CEVA's systems were compromised in the cyberattack, the exposed records belonged to Pokémon Center customers who submitted orders on the site. The company then shared this information with the logistics provider to fulfill and ship PokemonCenter.com orders.
CEVA Logistics is a subsidiary of the CMA CGM Group, the world's third-largest shipping company. The logistics provider operates 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenue in 2025.
Impact on Customers
Pokémon Center orders were canceled after the breach, with customers receiving notification emails stating that their orders were canceled due to an unforeseen fulfillment issue. The emails also informed customers that CEVA Logistics had been a victim of a cyber attack commencing on July 30, 2026.
Unauthorized parties may have obtained customers' full names, mailing addresses, phone numbers, email addresses, and details about the contents of their PokemonCenter.com orders. However, other information related to customers and their orders was not impacted, and CEVA does not have access to customers' payment card details.
Response and Next Steps
Pokémon Center is currently displaying a notice on its UK website warning that some orders are experiencing delays and may take longer than usual to process, dispatch, and deliver. Customers are advised to check their email for updates on their orders and to contact Pokémon Center customer support if they have any questions or concerns.
The breach has also raised questions about the security measures in place at CEVA Logistics and the impact on other retailers that use the logistics provider. As the investigation into the breach continues, customers are urged to remain vigilant and to monitor their accounts for any suspicious activity.
Related Incidents
The CEVA breach also affected Valve, which notified Steam hardware customers in Europe that their names, addresses, phone numbers, email addresses, and information about ordered products were stolen during the cyberattack.
The attack also disrupted eight of CEVA's European warehouses, causing shipping delays for many customers. The incident highlights the importance of robust security measures and incident response plans to minimize the impact of data breaches and cyberattacks.
Pokémon Center and CEVA Logistics have not responded to requests for comment on the breach and the cancellation of orders. The incident is a reminder of the risks associated with third-party data breaches and the need for companies to prioritize cybersecurity and data protection.
The Pokémon Center data breach is a significant incident that affects customers in the UK and Germany. As more information becomes available, customers will be updated on the next steps to take and the measures being implemented to prevent similar incidents in the future.
Conclusion
The Pokémon Center data breach is a serious incident that highlights the importance of robust security measures and incident response plans. Customers are urged to remain vigilant and to monitor their accounts for any suspicious activity. The incident is a reminder of the risks associated with third-party data breaches and the need for companies to prioritize cybersecurity and data protection.
As the investigation into the breach continues, customers can expect updates on the next steps to take and the measures being implemented to prevent similar incidents in the future. In the meantime, customers are advised to check their email for updates on their orders and to contact Pokémon Center customer support if they have any questions or concerns.
Source: BleepingComputer