If you are a customer of the Pokémon Center, a third-party data breach could mean that your information, including order details as well as names, addresses, phone numbers and email addresses, has been stolen Although Pokemon Center, the official outlet for Pokemon cards, toys and clothes, has not itself been hacked, email warnings were sent to customers in both the U.K. and Germany confirming that a supply chain attack has impacted them.
“CEVA Logistics (“CEVA”), the vendor Pokemon Center utilizes to ship product from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026,” the email stated, as reported by Bleeping Computer, August 17. I understand that CEVA did not have access to customer payment card details, and information other than that already mentioned has not been leaked.
The U.K. website of the Pokemon Center was, at the time of writing, displaying a prominent banner confirming that it is “currently experiencing delays in processing and shipping orders.” There was no mention of the data breach; I have reached out for a statement.
CEVA Logisitics Breach Impacts Pokemon And Steam Customers
The third-party whose breach is at the center of the issue, CEVA Logistics, used to ship products to both the U.K. and Germany, has been reported to have fallen victim to a cyberattack between July 29 and August 1, with vendors including Valve already having notified Steam users regarding stolen customer data. I have also reached out to CEVA Logisitics for a statement.
“For the security community, the message is straightforward: Your third-party risk programme needs to extend to logistics, fulfilment, and operational partners with the same rigour applied to technology vendors.” Muhammad Yahya Patel, vCISO and cybersecurity advisor at Huntress, said. Customers, however, simply trusted Pokemon Center, and didn’t sign up to trust their logistics provider. “That distinction matters,” Patel concluded, “and most consumers don’t know it exists until a breach notification lands in their inbox.” Supply chain attacks are not something you think of when ordering your Pokemon cards, after all.
“The information compromised is very significant, and it could be used in multiple ways to execute attacks,” Donnan Mallon, a threat intelligence analyst at Talion Cyber Security, told me. “Not only do attackers have full contact details for individuals,” Mallon said, “they also have information on orders, which could all be used to craft tailored phishing scams.” Pokemon Center customers in the U.K. and Germany should, therefore, be on high alert for phishing scams in the coming days and weeks.

