Pokémon Center has alerted customers in the UK and Germany following a massive third-party data breach at CEVA Logistics, resulting in stolen personal info and unexpected order cancellations.

  • Data breach occurred via third-party provider CEVA Logistics.
  • Affected data includes full names, mailing addresses, phone numbers, and emails.
  • Payment details remain secure as CEVA does not store credit card info.
  • Valve (Steam) hardware customers in Europe were also impacted by the same breach.

Pokémon Center is currently notifying its customer base in the United Kingdom and Germany about a significant security failure. The breach did not occur on Pokémon Center's own servers but through CEVA Logistics, a third-party logistics provider used to fulfill and ship orders for the region.

The cyberattack took place between July 29 and August 1, 2026. CEVA Logistics, a subsidiary of the shipping giant CMA CGM Group, manages an expansive network of 1,000 warehouses and reported revenues of $18.3 billion in 2025. The breach was widespread, affecting multiple European retailers, including Valve, which had to notify Steam hardware customers about the theft of their personal details.

Why This Matters

BozokMedia analysis shows that this incident is a textbook example of 'Supply Chain Vulnerability.' Even when a primary company maintains high security standards, the integration of third-party vendors creates an expanded attack surface. The fact that a logistics provider—not a payment processor—held enough PII (Personally Identifiable Information) to cause this level of disruption is a major red flag for data minimization practices.

"The shift toward targeting logistics providers allows hackers to hit multiple high-profile brands with a single point of entry, maximizing the impact of the breach."

According to notification emails, unauthorized parties may have accessed full names, mailing addresses, phone numbers, email addresses, and specific details regarding the contents of orders. While financial data is safe, the breach has caused operational chaos, leading to significant shipping delays and the mysterious cancellation of numerous orders.

Customers on platforms like Reddit have reported that even minor items, such as the Ghost Chateau Cyndaquil keyring, were affected by cancellations. This has sparked confusion, as a data breach typically leads to delays or security warnings, not the outright cancellation of retail orders.

Historical Background

Third-party breaches have become increasingly common in the e-commerce sector. From the Target breach of years past to recent cloud-service leaks, the trend shows that hackers are moving away from the 'front door' of a company and instead targeting the 'side doors'—the vendors and partners who have trusted access to customer data.

Affected Entity Data Compromised Region
Pokémon Center Name, Address, Email, Order Details UK & Germany
Valve (Steam) Name, Address, Phone, Email Europe
Did You Know?: Many logistics companies retain customer data for 90 days post-delivery, meaning your information remains at risk long after your package has arrived.

Frequently Asked Questions

Q1: Was my credit card information stolen?
No. Pokémon Center confirmed that CEVA Logistics does not have access to payment card details.

Q2: Why was my order canceled instead of just delayed?
Pokémon Center cited 'unforeseen fulfilment issues,' but the company has not yet provided a detailed explanation as to why a data breach necessitated cancellations.