Skip to main content
Emerging ThreatsSupply Chain Attacks

Supply Chain Hack Exposes Pokémon Center Customer Data

Rows of boxes and packages in a well-lit logistics facility with scattered shipping documents and a computer in the…

On July 30, CEVA informed the Pokémon Center that it had faced a cyberattack — a supply chain intrusion that, according to the Pokémon Center, exposed customer order details even though the retailer’s own systems were not directly breached.

CEVA Logistics: the conduit for exposed customer data

The Pokémon Center said the incident was not a direct compromise of its systems but a third-party breach that affected the company through a partner relationship with CEVA Logistics (“CEVA”), which handles shipments to customers in the United Kingdom and Germany. CEVA’s notification on July 30 is the proximate event the Pokémon Center identified as the source of the disruption and exposure.

Exactly which customer records were exposed

According to the Pokémon Center’s account, the data made accessible by the incident consisted of customer order details: names, email addresses, phone numbers, and physical addresses. The organization made a point of distinguishing those exposed order details from payment information, stating that payment card details should not be compromised by this event.

Supply chain attack, not a direct hack of the Pokémon Center

The Pokémon Center framed the episode as a supply chain compromise rather than a direct breach of its own infrastructure. That distinction matters to the organization’s public description: the data exposure occurred because a partner in the fulfillment chain was targeted, and that targeting had downstream effects on Pokémon Center customer data stored or processed in conjunction with CEVA’s services.

Operational impact: slowed dispatch, delayed and cancelled deliveries

The cyberattack has had a tangible operational effect on the Pokémon Center’s ability to serve customers. The company reported that the attack disrupted operations, slowing dispatch and delivery. Media reports have further noted that some deliveries were cancelled, though the Pokémon Center has not specified whether cancellations were a direct consequence of the breach, a precautionary operational decision, or the result of logistics failures tied to the attack.

What this means for technologists, affected customers, and procurement leaders

  • Technologists and security teams: The incident underscores that a partner’s incident can expose order-level customer data even when primary systems remain intact. Teams responsible for incident response and data flows will need to trace where customer order details are held or transmitted in third-party systems and assess containment measures consistent with the Pokémon Center’s account.
  • Affected customers: Individuals whose names, email addresses, phone numbers, and physical addresses were part of customer order records should be advised that those elements were exposed; the Pokémon Center’s notice that payment card details should not be compromised is a specific reassurance but does not eliminate other privacy or fraud risks tied to contact and address information.
  • Procurement and outsourcing leaders: The disruption highlights the operational consequences of logistics-provider compromises. Organizations that outsource fulfillment to third parties — particularly those serving cross-border customers, as CEVA does in the United Kingdom and Germany for the Pokémon Center — will evaluate contractual, technical, and oversight controls to limit data exposure and to preserve service continuity when a partner is breached.

Conclusion: clear facts, open operational questions

The core facts are sharp: CEVA notified the Pokémon Center on July 30 that it had experienced a cyberattack; customer order details including names, email addresses, phone numbers and physical addresses were exposed; the Pokémon Center itself says it was not hacked; and payment card details should not have been compromised. The attack has also slowed dispatch and delivery and led to some cancelled deliveries, though why particular shipments were cancelled has not been specified.

Those facts leave a narrow set of operational questions: where within the CEVA–Pokémon Center data flows the exposed records resided, what containment and notification steps were taken by both organizations, and whether any regulatory or remedial measures will follow. For customers, the immediate takeaway is the limited but specific set of exposed data and the assurance regarding payment card details; for partners and buyers of logistics services, the episode is a reminder that supply chain incidents can translate quickly into service disruption and privacy exposure.

Original reporting: https://www.securitymagazine.com/articles/102495-third-party-breach-exposes-pokemon-center-customer-data