Cyber Incident Victim: Pokémon Center
Timeline
Summary
Pokémon Center informed customers in the United Kingdom and Germany that a cyberattack on its logistics provider CEVA Logistics resulted in the theft of personal and order data, including names, addresses, phone numbers, email addresses and details of purchased items, while payment card information remained secure. The company said the breach also disrupted several of CEVA’s European warehouses, causing shipping delays and leading to the cancellation of some orders due to an unforeseen fulfilment issue. It noted that CEVA retains delivery‑related data for up to 90 days after an order, although it is unclear whether the same retention period applied to the affected customer records. The firm posted a notice on its UK website warning of extended processing times and has not offered further explanation for the order cancellations.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On July 30, 2026, CEVA Logistics informed Pokémon Center that it had been the victim of a cyber attack that began on that date, with attackers breaching CEVA's servers between July 29 and August 1, 2026. The breach affected multiple retailers in Europe, including Pokémon Center, whose customer order data was stored by CEVA to fulfill and ship purchases made on PokemonCenter.com. As a result of the compromise, unauthorized parties may have obtained customers' full names, mailing addresses, phone numbers, email addresses, and details about the contents of their PokemonCenter.com orders. Pokémon Center confirmed that CEVA does not have access to customers' payment card details and that no other order‑related information was impacted.

The breach led to disruptions in eight of CEVA's European warehouses, causing shipping delays for many customers and prompting Pokémon Center to cancel some orders that were affected by the unforeseen fulfilment issue. In breach notification emails, Pokémon Center told customers that their recent order had been canceled due to an unforeseen fulfilment issue and explained that a cyber incident affecting its logistics provider may have exposed some of their personal information. Customers in the United Kingdom and Germany also reported seeing a notice on Pokémon Center's UK website warning that some orders are experiencing delays and may take longer than usual to process, dispatch, and deliver. Although some customers noted that their orders were canceled rather than merely delayed, the source material notes that it is unclear why the cyberattack would require cancellations instead of simply delays.
Pokémon Center's response included sending data breach notification emails to affected customers in the United Kingdom and Germany, detailing the types of data that may have been accessed and stating that payment card information was not compromised. The company also posted a notice on its UK website to inform visitors about ongoing order delays and longer processing times. BleepingComputer attempted to obtain further clarification from Pokémon Center and its media contacts regarding the breach and the reasons for order cancellations, but did not receive a reply. No additional details about attacker actions, detection methods, or containment steps were provided in the source material.