Skip to main content
Emerging ThreatsData Breaches

Pokémon Center Breach Exposes Customer Data

Logistics warehouse interior with shelving, shipping containers, and scattered boxes and packages.

"We're sorry to inform you that we have had to cancel your recent order [order number] due to an unforeseen fulfilment issue," reads the notification Pokémon Center sent to some customers after a third‑party logistics provider, CEVA Logistics, was breached in late July and early August.

CEVA Logistics: scope, timing, and scale of the breach

CEVA Logistics, a subsidiary of the CMA CGM Group, suffered a cyberattack that breached its servers between July 29 and August 1, according to reporting. CEVA — part of the world’s third‑largest shipping company — operates roughly 1,000 warehouses, handled 15 million shipments last year, and the parent group reported $18.3 billion in revenue in 2025.

The incident affected multiple retailers in Europe and disrupted eight European warehouses, causing shipping delays for many customers. CEVA's role as a fulfillment and delivery partner places customer order and delivery records in its environment; the company told partners and affected vendors that attackers were able to access such records during the intrusion.

What Pokémon Center says and which customer data were exposed

Pokémon Center's notification to customers in the United Kingdom and Germany says CEVA is the vendor used to ship PokemonCenter.com orders to those markets. The message states that unauthorized parties may have obtained customers' full names, mailing addresses, phone numbers, email addresses, and details about the contents of their PokemonCenter.com orders.

The company also told customers that "other information related to customers and their orders was not impacted" and that CEVA does not have access to customers' payment card details. Pokémon Center is displaying a notice on its UK website warning that some orders are experiencing delays and may take longer than usual to process, dispatch, and deliver.

Ripple effects: Valve, Steam hardware customers, and retention questions

The CEVA breach also affected Valve. Valve notified Steam hardware customers in Europe that attackers stole names, addresses, phone numbers, email addresses, and information about ordered products during the cyberattack.

Valve's notification said CEVA retains delivery‑related information for up to 90 days after an order. Reporting notes it is unclear whether the same 90‑day retention period applies to Pokémon Center customer data — a specific point of uncertainty the notifications leave open.

Operational consequences: eight warehouses disrupted, canceled orders, and specific products affected

Beyond delays, some Pokémon Center customers report receiving cancellation emails rather than a notice of delayed delivery. Initial reports warned that cancellations affected the highly anticipated 30th anniversary collection. Social posts, including a Reddit thread noted in reporting, show other items were canceled as well — one example cited is the Ghost Chateau Cyndaquil keyring.

BleepingComputer contacted Pokémon Center and Pokémon media contacts to learn why the cyberattack led to cancellations in some cases and to seek further details, but had not received a reply at the time of reporting.

How customers, retailers, and logistics providers are likely to respond

  • Customers: Those notified will be focused on the exposed fields — names, mailing addresses, phone numbers, email addresses, and order contents — and on whether canceled purchases will be restocked or refunded. The Pokémon Center notifications and the UK site notice are the primary channels customers have for updates.
  • Retailers and e‑commerce teams: Companies that used CEVA for fulfillment will be watching for vendor retention policies (Valve reported a 90‑day retention window), the scope of affected warehouses, and whether fulfillment partners can guarantee separation of payment data from delivery records.
  • Logistics providers: CEVA’s disruption of eight European warehouses underscores the operational risk logistics providers face when their systems are breached; partners and customers will want clarity about which warehouses and shipment lanes were affected and for how long.

The breach leaves several concrete questions unanswered in the record: why some orders were canceled rather than merely delayed, whether Pokémon Center customer records are retained on the same 90‑day basis CEVA described to Valve, and how long the warehouse disruptions will continue. Those gaps matter to customers awaiting deliveries and to retailers that rely on third‑party fulfillment to connect products to buyers.

Original reporting: BleepingComputer