Pokémon Center Data Breach Impacts UK Customers After CEVA Logistics Cyberattack

A cyberattack on CEVA Logistics disrupted Pokémon Center UK orders, exposing customer data like names and addresses but keeping payment info safe. Learn what this means for affected users.

Pokémon Center Data Breach Impacts UK Customers After CEVA Logistics Cyberattack
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What happened in the Pokémon Center data breach?

A cyberattack targeted CEVA Logistics, the shipping partner for Pokémon Center UK and Germany, beginning July 30, 2026. This attack forced CEVA to partially shut down IT systems and operations, resulting in delays and cancellations of some Pokémon Center orders.

As a consequence, Pokémon Center UK had to cancel recent orders and notify customers about the fulfillment issues. The attack affected logistics workflows, causing longer processing and dispatch times for shipments.

What customer information was exposed and what remains secure?

Cyberattack on Ceva Logistics warehouses in Europe impacts retailers |  FreightWaves
Cyberattack on Ceva Logistics warehouses in Europe impacts retailers | FreightWaves

Due to this incident, personal data such as customer full names, mailing addresses, phone numbers, email addresses, and prior order details were likely exposed. However, crucially, user accounts and payment information were not compromised and remain secure.

This distinction is important: while personal contact details may be used for phishing or social engineering attempts, financial risk to customers is currently low since payment credentials were not leaked.

Which parties and regions were affected by this breach?

CEVA Logistics supports many major clients, and at least a dozen organizations reported impact from this cyberattack, including Pokémon Center UK and Germany, Dutch retailers, and a notable PC gaming company. The widespread nature of the breach underscores risks faced by companies relying on third-party logistics providers.

Currently, no group has taken responsibility for the attack, and investigations continue. This event highlights the importance of securing supply chains and partner systems to prevent cascading cybersecurity impacts.

How should affected customers respond to this breach?

DentaQuest Data Breach, CEVA Customer Exposure, Levi Strauss Attack –  Cybersecurity News [August 10, 2026] | DuoCircle
DentaQuest Data Breach, CEVA Customer Exposure, Levi Strauss Attack – Cybersecurity News [August 10, 2026] | DuoCircle

Customers who placed orders through Pokémon Center UK should be alert for phishing attempts using their exposed personal data. They should verify all communications carefully and avoid clicking suspicious links.

It is also a good opportunity to review privacy and security settings on related accounts and enable multi-factor authentication where possible. Although payment data was safe, vigilance is key to avoid fraud attempts leveraging leaked names or addresses.

Key takeaways for consumers and online shoppers

This incident illustrates the risks posed by cyberattacks on third-party logistics providers, which can disrupt supply chains and expose customer data beyond the primary retailer. For consumers, understanding that exposure of non-financial data can still increase phishing risks is crucial.

While payment information here was protected, customers should remain cautious and report suspicious activity promptly. Companies must also bolster security not only internally but throughout their partner networks to mitigate such vulnerabilities.

React to this story

Related Posts