Search TorNews

Find cybersecurity news, guides, and research articles

Popular searches:

Home » News » Data Breaches » Pokémon Center Data Breach Exposes UK and German Customer Information

Pokémon Center Data Breach Exposes UK and German Customer Information

By:
Last updated:August 18, 2026
Human Written
  • Pokémon Center has started alerting customers in the UK and Germany that a cyberattack on its shipping partner exposed their personal data.

  • The breach hit CEVA Logistics, not Pokémon Center’s own website, but customer names, addresses, phone numbers, and order details were all caught in the fallout.

  • The attack also disrupted at least eight warehouses across Europe and touched data from banks, other retailers, and gaming companies, including Valve.

Pokémon Center Data Breach Exposes UK and German Customer Information

Pokémon Center is sending breach notices to shoppers in the United Kingdom and Germany. A cyberattack on its shipping partner exposed their personal information. The incident also forced the company to cancel a number of pending orders.

The breach did not start on Pokémon Center’s own website. It started at CEVA Logistics, the company Pokémon Center uses to ship orders across the UK and Germany. Hackers broke into systems CEVA uses to handle delivery information for its retail clients. Pokémon Center customers got caught in the middle.

What Pokémon Center Told Affected Shoppers

Pokémon Center sent notification emails to affected customers. The company first apologized for canceling recent orders, citing what it called “an unforeseen fulfilment issue.” It then revealed the real reason. From the notice, Pokémon Center received information from CEVA Logistics that hackers attacked its systems on 30 July 2026.

The company confirmed what information the attackers may have accessed. That list includes customers’ full names, home addresses, phone numbers, email addresses, and details about their PokemonCenter.com orders.

Pokémon Center was clear about what was not affected. CEVA does not store payment card details, and other account information stays safe. Even so, names, home addresses, and order contents give criminals enough material to run convincing scams targeting Pokémon fans.

Pokémon Center’s UK website currently shows a notice warning shoppers that some orders may take longer than usual to arrive. Despite that message, several customers report their orders were fully canceled, not just delayed. It is still unclear why the breach led to cancellations rather than simple slowdowns.

A Much Bigger Attack on CEVA Logistics

The Pokémon Center situation is just one part of a far larger problem. CEVA Logistics is one of the world’s biggest shipping and contract logistics companies. CEVA verified to TechCrunch that the attack most likely hit on July 29, 2026. The intrusion disrupted up to eight (8) warehouses across Europe.

CEVA activated its security protocols as soon as it discovered the breach. On 1 August, the company told affected clients that a cyber intrusion was hitting part of its European contract logistics operations. CEVA also stressed that the damage stayed limited to those eight sites. No other CEVA systems around the world were affected.

The fallout, however, reached well beyond Pokémon merchandise. Reports show the breach also exposed customer data linked to banks, other retailers, and gaming companies. Valve, the company behind Steam, confirmed that hackers accessed some of its data through CEVA. Valve added that passwords and payment details were not exposed, given that CEVA had no access to them to begin with.

Data protection agencies in Dutch together with other law enforcement groups, are now looking into the incident. CEVA has not publicly named the attack method or linked the intrusion to any specific hacker group.

What Shoppers Should Do Now

Pokémon Center customers in the UK and Germany face a real risk of targeted scams. The stolen data is enough for criminals to write convincing phishing emails or fake delivery text messages. Those messages could reference real order numbers, making them harder to spot.

Shoppers should treat any unexpected message about a Pokémon Center order with suspicion. They should only check shipment or refund updates through official Pokémon Center channels directly. They should also watch out for fake emails pretending to come from courier companies.

The risk of these scams is not hypothetical. In a coordinated global enforcement operation spanning the DOJ, FBI, Meta, Microsoft, Coinbase, and Starlink, authorities removed more than 1.4 million fraudulent accounts, suspended roughly 20,000 malicious accounts, froze over $3 million in crypto, and arrested 63 individuals linked to scam networks operating from Southeast Asia.

The incident adds to a growing pattern in 2026. Attackers are increasingly going after logistics and shipping vendors instead of retailers directly. One warehouse breach can expose data from dozens of brands at once.

CEVA handled deliveries for banks, retailers, and gaming companies, so a single attack turned into a multi-company data leak. That strategy is becoming one of the most effective tools in a cybercriminal’s playbook.

Share this article

About the Author

Joahn G

Joahn G

Cyber Threat Journalist

Joahn is a cyber threat journalist dedicated to tracking the evolving landscape of digital risks. His reporting focuses on ransomware gangs, data breach incidents, and state-sponsored cyber operations. By analyzing threat actor motives and tactics, he provides timely intelligence that helps readers understand and anticipate the security challenges of tomorrow.

View all posts by Joahn G >
Comments (0)

No comments.