CyberSecurityNews

Pokémon Center Confirms Data Breach


Pokémon Center has begun notifying customers in the United Kingdom and Germany that their personal information was exposed in a third-party data breach, and that the incident has forced the company to cancel a batch of pending orders.

The retailer confirmed that the exposure did not originate on its own website but instead traced back to CEVA Logistics, the shipping vendor Pokémon Center relies on to fulfill Pokémon Center orders across the UK and Germany.

In breach notification emails sent to affected shoppers, Pokémon Center apologized for canceling recent orders “due to an unforeseen fulfilment issue,” before explaining the real cause: a cyberattack against its logistics partner. According to the notice, CEVA Logistics informed Pokémon Center that it had been the victim of a cyberattack that began on 30 July 2026.

The intrusion compromised systems CEVA uses to process delivery information for retail clients, and Pokémon Center customer records were caught in the fallout.

Pokémon Center Confirms Data Breach

Pokémon Center says the information unauthorized parties may have accessed includes customers’ full names, mailing addresses, phone numbers, email addresses, and details about the contents of their PokemonCenter.com orders.

The company was careful to note what was not affected, stating that CEVA does not have access to customers’ payment card details, and that other account information was not impacted by the incident. Still, the combination of names, home addresses, and order contents gives attackers enough material for convincing phishing or social engineering attempts targeting Pokémon collectors.

Pokémon Center’s UK website is currently displaying a notice warning shoppers that some orders are experiencing delays and may take longer than usual to process, dispatch, and deliver. Despite that messaging, a number of customers report their orders were outright canceled rather than simply delayed, and it remains unclear why the breach necessitated cancellations instead of processing slowdowns.

The Pokémon Center incident is one piece of a much larger breach at CEVA Logistics, one of the world’s largest shipping and contract logistics firms. CEVA confirmed to TechCrunch that the intrusion most likely began on 29 July 2026 and disrupted at least eight warehouses across Europe.

The company activated its security protocols upon discovery and told affected customers on 1 August that a cyber intrusion was impacting part of its European contract logistics operations, while stressing that the operational impact stayed contained to those eight sites and that no other CEVA systems globally were affected.

The ripple effects have reached well beyond Pokémon merchandise. Reporting indicates the breach also touched customer data tied to banks, other retailers, and gaming companies, including Steam parent company Valve, which said passwords and payment credentials were not exposed since CEVA never had access to them.

Dutch data protection authorities and other law enforcement agencies are now investigating the incident, and CEVA has not publicly disclosed the attack vector or attributed the intrusion to a specific threat actor.

For Pokémon Center shoppers in the UK and Germany, the exposed data is enough to fuel targeted phishing emails or fraudulent delivery scam texts referencing real order numbers. Security-conscious customers should treat any unsolicited message about a Pokémon Center order with suspicion, verify shipment or refund communications only through official Pokémon Center channels, and stay alert for spoofed emails impersonating couriers.

The incident also underscores a recurring theme in 2026’s threat landscape: attackers increasingly go after logistics and fulfillment vendors as a single point of entry into dozens of downstream retail brands, turning one warehouse compromise into a multi-company data exposure event.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.



Source link