Entertainment

Pokémon Center customers in the UK and Germany caught up in CEVA Logistics data breach

Vince MaglayaPublished 2w ago2 min readBased on 2 sources
Pokémon Center customers in the UK and Germany caught up in CEVA Logistics data breach
Photo by Edgar Almeida on Pexels

Pokémon Center has begun notifying customers in the UK and Germany that their personal information may have been exposed in a data breach at CEVA Logistics, the shipping company that delivers the store's orders across Europe.

CEVA Logistics, a global freight and delivery firm, handles shipments for Pokémon Center — the Pokémon Company's official online store for merchandise and collectibles. The store shares customer details with CEVA so the courier can complete deliveries, and it is that shared data that appears to have been caught in the breach.

According to CEVA's notification to Pokémon Center, the cyberattack began on 30 July 2026 (CybersecurityNews). Pokémon Center told affected customers the incident is believed to have taken place between 29 July and 1 August (Eurogamer).

The exposed information could include full names, mailing addresses, phone numbers, email addresses, and order details — up to and including the contents of the packages ordered. Pokémon Center has moved to cancel the orders of affected UK customers, and the breach is causing further delays in processing and shipping on the Pokémon Center UK website.

Payment and card details are safe, according to Pokémon Center, because the store does not share that information with CEVA. The breach is confined to the delivery data the courier needed to ship goods.

This is not the first fallout from the CEVA breach to surface. Days before Pokémon Center issued its notice, CEVA alerted Valve that the same hack had affected customers who ordered Steam hardware in Europe — making the shipping firm the common thread across two separate gaming-adjacent retailers.

For affected customers, the practical steps are straightforward: watch for phishing emails that reference real order details, since those are now potentially in the hands of attackers. A legitimate-looking message that name-drops a recent purchase is far more convincing than a generic scam, and the breached data includes exactly the kind of information that makes such messages persuasive. Changing account passwords and being cautious with any unsolicited contact about deliveries are reasonable precautions.

Neither Pokémon Center nor CEVA has said how many customers are affected across the UK and Germany. The investigation is ongoing.