Pokémon Center warns UK and German shoppers after shipping partner is hacked
A cyberattack on logistics firm CEVA has spilled names, addresses and order details of Pokémon Center customers, leaving some fans with cancelled orders and no timeline for resolution.

Key points
- Pokémon Center is telling shoppers in the United Kingdom and Germany that their personal details were exposed in a break-in at its shipping partner, CEVA Logistics.
- The hackers were inside CEVA's systems between 29 July and 1 August, according to notices sent to affected customers.
- Stolen data includes full names, mailing addresses, phone numbers, email addresses and details of items ordered on PokemonCenter.com.
- Payment card details were not taken, because CEVA never held them.
- Some customers, including buyers of 30th anniversary merchandise, have had their orders cancelled with no clear explanation.
Pokémon Center didn't get hacked. Its delivery company did.
The retailer is emailing shoppers in the UK and Germany to say that CEVA Logistics, the outside firm it pays to pack and ship orders from PokemonCenter.com, was broken into over the summer. Because Pokémon Center hands CEVA the details needed to deliver a parcel, those details ended up within the hackers' reach.
The emails, first reported by BleepingComputer, tell customers that attackers may have taken their full name, address, phone number, email address and a description of what they ordered. No card numbers were exposed. CEVA never sees them.
What actually happened at CEVA?
Criminals broke into CEVA's computer systems between 29 July and 1 August and rifled through data belonging to several European retailers. CEVA is a subsidiary of CMA CGM, the world's third-largest shipping company. It runs 1,000 warehouses and moved 15 million shipments last year.
The same intrusion also hit Valve, the company behind the Steam gaming platform. We reported on 10 August that Valve had to warn European buyers of Steam hardware that their delivery details were stolen in exactly the same attack. Eight of CEVA's European warehouses were disrupted, which is why parcels across the continent have been slow.
CEVA told Valve it keeps delivery information for up to 90 days after an order ships. Whether that window applies to Pokémon Center shoppers isn't yet clear.
What was taken, and from whom?
| Detail | What we know |
|---|---|
| Retailer notifying customers | Pokémon Center (UK and Germany) |
| Third party breached | CEVA Logistics |
| Dates of intrusion | 29 July to 1 August |
| Data exposed | Name, address, phone, email, order contents |
| Data not exposed | Payment card details |
| Other confirmed victim | Valve (Steam hardware buyers in Europe) |
Why are orders being cancelled?
Alongside the breach notice, Pokémon Center is telling some shoppers their orders have been scrapped entirely, citing an "unforeseen fulfilment issue". The UK site carries a banner warning of delays.
Cancellations are a step beyond delays. Fans on Reddit have reported losing orders for the 30th anniversary range; a Ghost Chateau Cyndaquil keyring was also pulled, according to posts BleepingComputer spotted. Pokémon Center hasn't explained why a shipping problem requires killing orders rather than pausing them, and hasn't responded to press questions.
Should Pokémon Center customers be worried?
There's no sign of stolen card details, so this isn't a wallet emergency. It's a phishing risk. Phishing is when criminals send fake emails or texts dressed up to look like a real company, hoping you'll click a link or hand over a password.
Someone holding your name, mailing address and a record of the Pokémon merchandise you just bought can write a convincing fake "delivery update" message. Treat any unexpected email or SMS about your order with suspicion. Don't click links inside it. Go to PokemonCenter.com directly and check order status there.
If your order was cancelled, your money should be refunded to the card you paid with. Watch your statement and chase the retailer if a refund doesn't appear within a normal working week.
This is a well-worn story wearing a new logo. The Trezor breach we covered on 13 August shows the same pattern: a logistics partner gets hit, customers carry the risk, and the retailer spends days explaining why something that wasn't their server still became their problem. Retailers won't shake this liability until they audit what their fulfilment partners actually retain.



