A major Pokémon Center data breach has exposed customer information and led to the cancellation of some orders. The breach, which occurred at third-party logistics provider CEVA Logistics, has affected customers in the United Kingdom and Germany who placed orders on the Pokémon Center website.
The incident began with a cyberattack on CEVA’s servers between July 29 and August 1. This attack compromised multiple retailers in Europe, including Valve, which notified its Steam hardware customers that their names, addresses, phone numbers, email addresses, and information about ordered products had been stolen. The CEVA breach also disrupted eight of its European warehouses, causing shipping delays for many customers.
Pokémon Center has since sent notification emails to affected customers, stating that their recent orders have been canceled due to an “unforeseen fulfillment issue.” However, the company’s data breach notifications reveal a more sinister truth: unauthorized parties may have obtained customers’ full names, mailing addresses, phone numbers, email addresses, and details about the contents of their Pokémon Center orders. Other information related to customers and their orders was not impacted, but CEVA does not have access to customers’ payment card details.
The exact reason for canceling affected orders is unclear, but it’s possible that the breach has compromised the security of these transactions. This raises serious concerns about the potential consequences of this breach, including identity theft and financial loss.
Pokémon Center is currently displaying a notice on its UK website warning that some orders are experiencing delays due to the CEVA breach. However, customers have reported receiving cancellation emails for various merchandise items, not just the highly anticipated 30th anniversary collection products.
It’s worth noting that Pokémon Center uses CEVA as a vendor to ship products from its website to customers in the United Kingdom and Germany. This highlights the importance of third-party risk management in cybersecurity – when one partner is breached, it can have far-reaching consequences for other companies involved in the supply chain.
The incident serves as a reminder that even well-known brands like Pokémon Center are not immune to cyberattacks. As we rely increasingly on online services and digital transactions, it’s essential to stay vigilant and take steps to protect ourselves from data breaches and cyber threats.
So what can customers do to minimize their exposure? For starters, monitor your accounts for suspicious activity and be cautious of any unsolicited emails or phone calls asking for personal information. If you’re affected by the breach, contact Pokémon Center’s customer support team to discuss potential next steps. By staying informed and taking proactive measures, we can reduce the impact of data breaches like this one.
Source: Bleeping Computer — 2026-08-17