> Back to All Posts

Pokémon Center Data Breach Hits UK and German Shoppers

Pokémon Center data breach

Pokémon fans in the United Kingdom and Germany opened their inboxes this week to unwelcome news. The Pokémon Center data breach exposed personal details belonging to customers who ordered merchandise from the official online store. Attackers never touched Pokémon Center’s own systems, though. They broke into CEVA Logistics, the shipping partner that handles deliveries for the site across both countries.

Notification emails started landing after CEVA confirmed the intrusion to its clients. Names, addresses, phone numbers and order contents all sat inside the stolen records. Some shoppers also found their purchases cancelled with almost no explanation. So the incident has left buyers facing a privacy problem and a missing parcel at the same time.

How the Pokémon Center data breach started with a shipping vendor

CEVA Logistics is not a household name, but it moves an enormous volume of parcels. The company runs roughly 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenue during 2025. It belongs to the CMA CGM Group, the third largest shipping company in the world.

Attackers sat inside CEVA’s servers between 29 July and 1 August 2026. Pokémon Center points to 30 July as the start of the attack in its customer notice. The intrusion also disrupted eight European warehouses and slowed deliveries for several retailers.

Because CEVA stores delivery data on behalf of the brands it serves, one break-in spilled across many separate customer bases. Pokémon Center handed over shopper information so the logistics provider could pack and ship PokemonCenter.com orders. That handoff is routine in e-commerce. However, it means your details live in systems you never chose and cannot inspect. The Pokémon Center data breach happened entirely inside one of those systems.

What the Pokémon Center data breach exposed

Pokémon Center told customers that unauthorised parties may have obtained several categories of personal data. The list covers full names, mailing addresses, phone numbers and email addresses. It also includes details about the contents of each order placed through the store.

Payment card data stayed out of reach, because CEVA never had access to it in the first place. Other account information tied to customers and their orders escaped the theft as well. That limits the immediate financial damage. Still, the exposed records remain valuable to fraudsters, since they describe real people, real homes and real purchases.

Why some Pokémon Center orders were cancelled

Shoppers began reporting cancellation emails soon after the first breach notices went out. The messages blamed an unforeseen fulfilment issue rather than naming the cyberattack directly. Pokémon Center has not explained why a security incident would force cancellations instead of simple delays. Both the Pokémon Center data breach and the cancellations arrived in the same week, so customers connected the two themselves.

Early complaints focused on the 30th anniversary collection, a release collectors had waited months to receive. Other buyers lost smaller items, including a Ghost Chateau Cyndaquil keyring. Meanwhile, the UK storefront continues to warn that orders may take longer than usual to process, dispatch and deliver.

Valve customers caught in the same attack

The Pokémon Center data breach formed one piece of a much wider fallout. Valve notified Steam hardware buyers across Europe that the same intrusion exposed their information. Stolen records there included names, addresses, phone numbers, email addresses and details of the products people ordered.

CEVA retains delivery-related information for up to 90 days after an order, according to the notice Valve sent its own customers. Nobody has confirmed that the same retention window applies to Pokémon Center shoppers, though. So affected buyers cannot easily judge how far back their exposure reaches.

The phishing risk created by the Pokémon Center data breach

Stolen shipping data makes unusually convincing bait. A scammer who knows your name, your address and your recent order can write a message that feels completely legitimate. Add a cancelled order into that mix, and a fake reorder link becomes very easy to believe.

Expect delivery-themed lures over the coming weeks. Fraudsters often pose as couriers, request a small redelivery fee, and harvest card numbers in the process. Others send refund forms that quietly collect enough personal information for an account takeover later on.

How to protect yourself after the Pokémon Center data breach

Nobody can undo the exposure, but a few habits reduce what criminals can do with the data.

Treat delivery messages with suspicion

Visit the retailer’s website directly instead of tapping links inside delivery texts or emails. Check your order status from within your account, because genuine updates appear there too. If a message demands payment for redelivery, delete it and move on.

Secure the accounts tied to your email

Change your password anywhere you reused the one linked to your store account. Turn on two-factor authentication, and watch for login alerts from unfamiliar locations. Because your email address is now circulating, expect both more spam and more targeted attempts.

Share less at checkout next time

Use a masked or secondary email address for retail orders where the option exists. Leave optional fields blank, especially phone numbers that stores rarely need. A VPN adds another layer by encrypting your traffic and hiding your IP address on shared networks, which limits what network operators and advertisers can tie back to you.

Final Thoughts

The Pokémon Center data breach follows a pattern that keeps repeating across online retail. Shoppers trusted a brand they recognised, yet their details ended up inside a contractor they never chose. Supply chain incidents like this one widen the pool of personal data available to fraudsters every single month.

Customers cannot audit every vendor sitting behind an online store. They can, however, control what they hand over, how they react to unexpected messages, and how fast they lock down affected accounts. Those habits will not stop the next breach, but they blunt its impact when it arrives.

Janet Andersen

Janet is an experienced content creator with a strong focus on cybersecurity and online privacy. With extensive experience in the field, she’s passionate about crafting in-depth reviews and guides that help readers make informed decisions about digital security tools. When she’s not managing the site, she loves staying on top of the latest trends in the digital world.