Pokémon Center Data Breach Exposes Customer PII to Hackers
Key Takeaways Personal data belonging to Pokémon Center customers in the UK and Germany was exposed in a third-party data breach. The incident originated at CEVA Logistics, Pokémon Center’s...
Key Takeaways
- Personal data belonging to Pokémon Center customers in the UK and Germany was exposed in a third-party data breach.
- The incident originated at CEVA Logistics, Pokémon Center’s shipping partner for these regions.
- Compromised data includes names, addresses, phone numbers, email addresses, and order contents, but not payment information.
- The breach led to the cancellation of numerous pending Pokémon Center orders.
- The larger CEVA Logistics cyberattack impacted at least eight European warehouses and affected multiple other clients.
Pokémon Center has initiated notifications to customers in the United Kingdom and Germany regarding a data breach at a third-party vendor, which resulted in the exposure of personal identifiable information (PII) and the subsequent cancellation of numerous pending orders.
Table Of Content
The popular retailer clarified that its own systems were not compromised. Instead, the data exposure stemmed from an incident at CEVA Logistics, the shipping provider responsible for fulfilling Pokémon Center orders across the UK and Germany.
Affected customers received breach notification emails from Pokémon Center, which initially cited an “unforeseen fulfilment issue” for the order cancellations. The communication subsequently detailed the true cause: a cyberattack targeting its logistics partner. According to the notice, CEVA Logistics informed Pokémon Center that it had fallen victim to a cyber incident that commenced on July 30, 2026.
Pokémon Center Data Exposed
The intrusion specifically impacted systems CEVA Logistics utilizes for processing delivery information for its retail clientele, leading to the compromise of Pokémon Center customer records.
Pokémon Center confirmed that the information potentially accessed by unauthorized parties includes customers’ full names, postal addresses, telephone numbers, email addresses, and specific details regarding the contents of their PokemonCenter.com orders.
Crucially, the company emphasized that CEVA Logistics does not handle customers’ payment card details, and therefore, no financial information or other account credentials were affected by this incident. Nevertheless, the combination of names, home addresses, and order specifics provides threat actors with sufficient material to craft highly convincing phishing or social engineering campaigns targeting Pokémon collectors.
Currently, Pokémon Center’s UK website displays a notice warning patrons of potential delays in order processing, dispatch, and delivery. Despite this general messaging, numerous customers have reported outright cancellations of their orders rather than mere slowdowns, leaving the precise rationale behind the cancellations unclear.
Wider Impact of CEVA Logistics Breach
The Pokémon Center incident is part of a significantly larger cyberattack targeting CEVA Logistics, a global leader in shipping and contract logistics. CEVA confirmed to TechCrunch that the intrusion likely began on July 29, 2026, and caused disruptions across at least eight of its warehouses in Europe.
Upon detection, CEVA Logistics activated its security protocols. On August 1, the company informed affected clients that a cyber intrusion was impacting a segment of its European contract logistics operations. CEVA stressed that the operational impact was confined to these eight sites and did not extend to other CEVA systems globally.
The repercussions of this breach have extended beyond Pokémon merchandise. Reports indicate that customer data linked to banks, various other retailers, and gaming companies were also affected. This includes Valve, the parent company of Steam, which stated that no passwords or payment credentials were exposed, as CEVA Logistics never had access to such sensitive information.
Dutch data protection authorities and other law enforcement agencies are actively investigating the incident. As of now, CEVA Logistics has not publicly disclosed the attack vector or attributed the intrusion to any specific threat actor.
For Pokémon Center customers in the UK and Germany, the exposed data is sufficient to facilitate targeted phishing emails or fraudulent delivery scam texts that could reference real order numbers. Security-conscious individuals should exercise extreme caution with any unsolicited communications concerning a Pokémon Center order. It is advisable to verify all shipment or refund-related messages exclusively through official Pokémon Center channels and remain vigilant for spoofed emails impersonating legitimate couriers.
This incident also highlights a pervasive trend in the 2026 threat landscape: cybercriminals increasingly target logistics and fulfillment vendors. These entities often serve as a single point of entry, enabling attackers to compromise dozens of downstream retail brands and transform one warehouse breach into a widespread multi-company data exposure event.
What You Should Do
- Be Vigilant Against Phishing: Exercise extreme caution with any unsolicited emails or texts regarding Pokémon Center orders, especially those requesting personal information or clicking links.
- Verify Communications Directly: If you receive suspicious messages about your order, do not respond directly. Instead, log into your official Pokémon Center account or contact their customer service through official channels to verify information.
- Monitor Financial Statements: While payment information was not compromised, it’s always good practice to regularly review bank and credit card statements for any unauthorized activity.
- Enable Multi-Factor Authentication (MFA): Where available, ensure MFA is enabled on your Pokémon Center account and any other online accounts to add an extra layer of security.
- Update Passwords: Consider updating passwords for your Pokémon Center account and any other online retail accounts, especially if you reuse passwords across multiple services.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.