Pokémon Center data breach exposes customer info, cancels some orders
Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]
Source: BleepingComputer · August 17, 2026 at 7:30 PM · AI-assisted report

KUALA LUMPUR, 18 AUGUST 2026 —
Listen to this article
DomainFork Audio · read aloud
Pokémon Center Data Breach Exposes UK, Germany Customers’ Info; Orders Cancelled
Market Impact
LONDON/KUALA LUMPUR — Pokémon Center is notifying customers in the United Kingdom and Germany that their personal and order information was exposed in a cyberattack targeting third-party logistics provider CEVA Logistics, the company said in breach notifications seen by BleepingComputer.
The breach occurred between July 29 and August 1, 2026, when attackers compromised CEVA Logistics’ servers, affecting multiple retailers in Europe. While CEVA’s systems were targeted, the exposed records belonged to Pokémon Center customers who submitted orders on its website. Pokémon Center shared this customer data with CEVA to fulfill and ship orders from PokemonCenter.com.
CEVA Logistics, a subsidiary of CMA CGM Group—the world’s third-largest shipping company—operates 1,000 warehouses globally, handled 15 million shipments in 2025, and reported $18.3 billion in revenue for the same year. The cyberattack disrupted operations at eight of its European warehouses, leading to shipping delays for affected customers.
Pokémon Center confirmed in its breach notification that unauthorized parties may have obtained customers’ full names, mailing addresses, phone numbers, email addresses, and details about their PokemonCenter.com orders. The company stated that CEVA does not have access to customers’ payment card details and that other customer information remained unaffected.
However, customers reported that some orders—including highly anticipated 30th anniversary collection products and merchandise such as the Ghost Chateau Cyndaquil keyring—were cancelled rather than delayed. Pokémon Center’s UK website currently displays a notice warning that some orders are experiencing delays and may take longer than usual to process, dispatch, and deliver.
The breach also impacted Valve, which notified Steam hardware customers in Europe that their names, addresses, phone numbers, email addresses, and product order details were stolen during the same cyberattack. CEVA Logistics retains delivery-related information for up to 90 days after an order, though it remains unclear whether the same retention period applies to Pokémon Center customer data.
Pokémon Center did not immediately respond to requests for clarification on why orders were cancelled instead of delayed. BleepingComputer contacted both Pokémon Center and Pokémon media contacts for further details but received no reply.
The incident highlights ongoing vulnerabilities in third-party logistics providers, which handle vast volumes of customer data and shipments. CEVA Logistics’ scale—processing 15 million shipments annually—underscores the potential impact of such breaches on global retail operations.
For Malaysian customers who may have ordered from PokemonCenter.com, the breach raises concerns about data security in cross-border e-commerce. While the notification specifically mentions UK and Germany, affected customers could include Malaysians who used the site for international shipping.
Industry experts emphasize the importance of robust third-party vendor risk management, particularly for companies handling sensitive customer information. The breach follows a pattern of increasing cyber threats targeting logistics and supply chain networks, which are critical to global trade.
Pokémon Center has advised affected customers to monitor their accounts for suspicious activity and contact customer support for further assistance. The company has not disclosed whether additional regions beyond the UK and Germany may be impacted.
As investigations continue, the incident serves as a reminder for businesses and consumers alike to prioritize cybersecurity measures, including regular audits of third-party vendors and encryption of sensitive data.