Pokémon Center informed customers in the United Kingdom and Germany that their personal data and order information may have been exposed following a breach affecting the systems of logistics company CEVA Logistics, which handles shipping for PokemonCenter.com products in both markets. According to notices reviewed by BleepingComputer, the incident involved customers’ names, postal addresses, phone numbers, email addresses, and details about the contents of their orders.
The breach occurred in CEVA’s systems between July 29 and August 1, 2026, while Pokémon Center’s message indicates that the attack began on July 30. The company uses customer data collected when orders are placed and then shares it with the logistics provider to fulfill and ship orders.
What data may have been exposed?
Pokémon Center said unauthorized parties may have obtained information associated with customers’ identities and purchase orders. However, it explained that other customer- and order-related information was not affected, and that CEVA does not have access to payment card data.
It remains unclear whether the data will continue to be retained by CEVA after orders have been fulfilled. Valve, whose customers were affected by the same attack, said that CEVA retains delivery information for up to 90 days after an order, but Pokémon Center has not confirmed whether the same period applies to its customers’ data.
Shipping delays and the cancellation of some orders
The impact of the attack was not limited to the potential exposure of data. The breach disrupted eight European warehouses operated by CEVA, resulting in delays in processing, preparing, and delivering shipments. Pokémon Center is also displaying an alert on its UK website warning customers that some orders may take longer than usual.
In messages sent to customers, the company said it had been forced to cancel some orders because of what it described as an unexpected issue with order fulfillment. Customers reported cancellations of products from the 30th anniversary collection, as well as other items such as the Ghost Chateau Cyndaquil keychain. The company did not explain why the incident led to cancellations in some cases instead of only delaying delivery.
Why does this incident matter?
The incident shows that a breach at an external provider can directly affect store customers, even when the store’s own systems were not compromised. Data required for shipping, such as names, addresses, phone numbers, and order contents, was held by the logistics provider and could become part of the incident’s scope.
The breach’s consequences extend beyond Pokémon Center; Valve said that the names, addresses, phone numbers, email addresses, and information about products ordered by European Steam device customers were stolen in the same attack. CEVA is affiliated with the CMA CGM Group and operates approximately 1,000 warehouses, while it handled 15 million shipments during the past year and recorded revenue of $18.3 billion in 2025.
BleepingComputer contacted Pokémon Center and media representatives associated with Pokémon products for additional details about why orders were canceled, but had not received a response by the time the report was published.