HomeYoutubePokémon Center: Data breach affects customers in Britain and Germany

Pokémon Center: Data breach affects customers in Britain and Germany

Pokémon Center customers in the UK and Germany are on alert after it was revealed that personal data and order information may have been exposed in a cyberattack targeting a third-party partner. The breach did not occur directly at Pokémon Center's IT systems, but at CEVA Logistics , which handles and ships orders from PokemonCenter.com to those markets.

The incident highlights once again the risk posed by supply chains. A company may maintain strong defenses in its own systems, but its customer data is still exposed when it is transferred to external partners to perform daily tasks.

What data may have been stolen

According to the information received by customers, unauthorized persons may have gained access to names, postal addresses, telephone numbers, email addresses and information regarding the content of orders.

See also: France: Data breach in tax administration affects 678,000 citizens

Pokémon Center clarifies that other data associated with accounts and orders was not affected. Most importantly, CEVA did not have access to the bank card used for purchases, thus limiting the risk of direct financial fraud through this data.

However, contact details and purchase information can be used in particularly convincing phishing attacks. A fraudster who knows what product someone ordered, their address and email address can create a message that looks completely trustworthy and attempt to extract additional credentials or financial information.

Pokémon Center: Data breach affects customers in Britain and Germany

The attack on CEVA affected many retailers

CEVA Logistics is a subsidiary of the CMA CGM and one of the world's leading logistics providers. It operates around 1,000 warehouses and handled 15 million shipments last year, recording revenues of $18.3 billion in 2025.

The attackers breached the company's servers between July 29 and August 1, 2026, causing problems for European businesses that rely on its services. The attack also affected eight warehouses in Europe, resulting in delays in order processing and delivery.

The Pokémon Center case is not unique. Valve informed customers in Europe (who had purchased hardware for Steam) that their personal information had been exposed in the same attack. The data included names, addresses, phone numbers, emails, and information about products they had ordered.

Why were orders cancelled?

Pokémon Center has notified some customers that their orders have been canceled due to the incident. In the same communication, the company explains that CEVA, as a shipping partner for the United Kingdom and Germany, informed the company about the cyberattack that began on July 30.

See also: SafePal incident: Data leak affects 39,798 customers

It is not yet clear why specific orders were canceled rather than simply delayed. The issue has caused a backlash among customers, as it appears that different product categories were affected, not just collector's editions.

Initial reports indicated that products related to the highly anticipated 30th anniversary collection were being canceled. However, user reports indicate that other products, such as the "Ghost Chateau Cyndaquil" keychain, were also affected.

Pokémon Center: Data Breach

The notification and delays continue

The Pokémon Center has posted a related update on its UK website, warning that some orders may take longer to process, ship, and deliver.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Meanwhile, questions remain about the extent of the leak and the length of time the data was accessible. Valve has said that CEVA retains delivery information for up to 90 days after an order is completed, but it has not been clarified whether the same policy applies to Pokémon Center data.

Another lesson in supply chain security

The incident demonstrates that cybersecurity does not stop at the boundaries of a company. Logistics partners, cloud providers, payment platforms and any third party that processes data can be critical links in the protection chain.

See also: Threema: Major outage from series of DDoS attacks

For customers, the most important thing is to be suspicious of emails that mention orders, refunds, or alleged delivery problems. After such a leak, attackers have enough information to make a phishing message much more convincing. So far, Pokémon Center has not provided further details about the incident or explained the reasons for the cancellations, while relevant questions to the company have not been answered.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS