Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center Suffers Data Breach Exposing Customer Information and Canceling Orders

In a concerning development, Pokémon Center has announced that it has suffered a data breach after hackers targeted its third-party logistics provider, CEVA Logistics. The incident has exposed customer personal and order information for customers in the United Kingdom and Germany, prompting the company to cancel some orders.

The cyberattack on CEVA’s systems compromised records belonging to Pokémon Center customers who submitted orders on the site. These details were then shared with CEVA to fulfill and ship PokémonCenter.com orders. It is unclear how long CEVA retains customer data after an order has been processed, but it appears that sensitive information was left vulnerable.

CEVA Logistics is a subsidiary of CMA CGM Group, one of the world’s largest shipping companies. The logistics provider operates over 1,000 warehouses and handled nearly 15 million shipments last year, generating $18.3 billion in revenue in 2025. CEVA recently suffered a cyberattack that affected multiple retailers in Europe, including Valve, which notified Steam hardware customers in Europe of a data breach.

The Pokémon Center notification emails seen by BleepingComputer reveal that the company uses CEVA to ship products to customers in the UK and Germany. The emails state that “unforeseen fulfillment issues” led to order cancellations, but it is unclear why this was necessary rather than simply experiencing delays. Customers have reported receiving cancellation notifications for various merchandise items, including some from the highly anticipated 30th anniversary collection.

The data breach has raised concerns about customer trust in online retailers and their third-party partners. CEVA’s cyberattack highlights the vulnerability of complex supply chains to targeted attacks. As more companies rely on outsourcing logistics and other services, they must prioritize cybersecurity measures to prevent similar incidents.

For customers affected by this incident, it is essential to remain vigilant and monitor their financial accounts for any suspicious activity. It is also crucial to keep an eye out for phishing emails or calls that may be attempts to exploit the breach further. Pokémon Center recommends that customers review their account information regularly and report any discrepancies to the company.

In light of this data breach, online retailers must reassess their relationships with third-party logistics providers and prioritize robust cybersecurity measures to protect customer data. By doing so, they can prevent similar incidents in the future and maintain customer trust.


Source: Bleeping Computer — 2026-08-17