← Blog

Pokémon Center Breach: CEVA Leak Hits UK and Germany

Share on X

Pokémon Center is emailing customers in the United Kingdom and Germany that a cyberattack on shipper CEVA Logistics may have exposed their names, mailing addresses, phone numbers, email addresses, and what they ordered. Some recent PokemonCenter.com orders were cancelled. Payment cards were not in CEVA’s systems, the company says.

If you bought plush, TCG product, or anniversary merch through the UK or German Pokémon Center site this summer, this is the same European warehouse incident that already hit Valve / Steam hardware, Bol, Ajax, and other brands. Canonical record: pokemon-center-ceva2026.

What happened in the Pokémon Center data breach

BleepingComputer reported on 17 August 2026 that Pokémon Center is notifying UK and German customers after hackers stole personal and order information from third-party logistics provider CEVA Logistics. CEVA’s systems were the ones compromised. The records belonged to Pokémon Center customers whose orders were sent to CEVA to pack and ship.

The customer email, as quoted by BleepingComputer, opens with an order cancellation, then explains the incident:

“We’re sorry to inform you that we have had to cancel your recent order [order number] due to an unforeseen fulfilment issue.” Then: CEVA, “the vendor Pokémon Center utilizes to ship product from PokemonCenter.com for customers in the United Kingdom and Germany,” told the brand it was “a victim of a cyber attack commencing on 30 July, 2026.”

That date sits inside the window Valve already published for the same shipper: attackers on CEVA servers between 29 July and 1 August 2026. FreightWaves and TechCrunch covered the European warehouse disruption earlier in August — eight warehouses, shipping delays, a cluster of retailer notices. Pokémon Center is a late notice in that cluster, not a separate mystery campaign.

CEVA is a CMA CGM subsidiary: about 1,000 warehouses, 15 million shipments last year, $18.3 billion in 2025 revenue, per BleepingComputer’s summary. Scale is why one warehouse week became a multi-logo notification month.

The UK Pokémon Center site has been showing a delay warning: some orders may take longer than usual to process, dispatch, and deliver. Customers separately report cancellations. BleepingComputer asked Pokémon Center and Pokémon media contacts why a shipper breach required cancellations rather than delays and had not received a reply at publication.

What data was exposed — and what was not

Pokémon Center says unauthorised parties may have obtained:

  • Full names
  • Mailing addresses
  • Phone numbers
  • Email addresses
  • Details about the contents of PokemonCenter.com orders

The company says other customer and order information was not impacted, and that CEVA does not have access to payment-card details.

That is the same shape as Valve’s Steam hardware notice: doorstep identity plus SKU, not a store-account password dump. You do not need to assume your Pokémon Trainer Club password or a saved card on pokemoncenter.com left CEVA. You should assume a scammer can quote your street and a recent plush or booster SKU.

Valve said CEVA retains delivery-related information for up to 90 days after an order. BleepingComputer notes it is unclear whether the same retention clock applies to Pokémon Center data. Until the brand says otherwise, treat recent UK/DE shipments — not only parcels that were physically in a warehouse on 30 July — as in play if you received the email.

What this is not: a Nintendo Account breach, a Pokémon GO account dump, or evidence that every Pokémon Center shopper worldwide is in the file. The notice names the UK and German PokemonCenter.com fulfilment path through CEVA. North American or Japanese storefronts are not described in the email BleepingComputer published.

Why some orders were cancelled

Delay notices and cancellation notices are different products. A delay says the warehouse is slow. A cancellation says the order will not ship as placed, with a refund implied in the usual ecommerce flow even if the email is clumsy about it.

Customers first flagged cancellations on highly anticipated 30th anniversary collection products. A Reddit thread then showed other merch — including a Ghost Chateau Cyndaquil keyring — getting the same cancellation language. Another shopper replied that they had the same mail.

BleepingComputer says it is unclear why the cyberattack would require cancellations rather than delays. Plausible operational reasons, none of them attested by the company: warehouse applications offline, pick-lists untrustworthy, allocation systems out of sync with stock, or a decision to kill in-flight orders rather than risk shipping to a tampered address file. Treat those as guesses. The attested facts are: CEVA was hit commencing 30 July; Pokémon Center cancelled some UK/DE orders; the brand also warned of delays on the UK site.

If you paid and the order was cancelled, watch the original payment method for a reversal. Do not “confirm a refund wallet” or “re-pay shipping” from a follow-up SMS.

Timeline

  1. 29 July – 1 August 2026 — Valve: attackers accessed CEVA servers used for European Steam hardware shipping data.
  2. 30 July 2026 — Pokémon Center email: CEVA cyberattack commencing this date.
  3. ~1 August — CEVA disruption of eight European warehouses; Ace & Tate and other brands already describing packing/shipping impact.
  4. 5–10 August — Bol, De Bijenkorf, Ajax, ING loyalty shop, Ace & Tate, Valve public notices; Dutch DPA told TechCrunch it had received reports from 10 organisations.
  5. 17 August 2026 — BleepingComputer publishes Pokémon Center’s UK/Germany customer emails and the delay banner on the UK site.

Pokémon Center is more than a week behind Valve’s 10 August mail. That lag is normal in 3PL incidents: the shipper investigates, then each brand maps which customer rows sat in the retained set, then legal signs letters. It is painful if you were waiting on anniversary product. It does not mean Pokémon Center invented a second breach.

Who is at risk

UK and German PokemonCenter.com shoppers whose orders went through CEVA. If you got the email, assume the listed fields may be out. If you ordered in that path inside a typical shipper retention window and have not seen mail yet, watch the inbox you used at checkout — including spam.

Gift recipients at the shipped address. The name on the box is what attackers see. Parents who ordered for a child should brief whoever answers the door and the family phone.

People chasing 30th anniversary and TCG drops. Scalper and “restock” phishing already targets this community. A real order SKU in a stolen file makes a fake Discord “warehouse hold” or “PayPal invoice” much more convincing.

Not automatically every Pokémon fan. US pokemoncenter.com orders, in-store Tokyo purchases, and Nintendo eShop digital games are outside this notice as described. Copycat phishing will still try to scare them.

Other CEVA retail clients still counting. Pokémon Center joining Valve is another logo on the same European contract-logistics failure.

Phishing you should expect

Attackers who know you bought Pokémon merch, where it was going, and which SKU you wanted will not send generic “your account is locked” mail. Expect:

  • “Pokémon Center: pay a customs fee to release your anniversary box”
  • “CEVA / DHL redelivery — click to reschedule”
  • Discord or WhatsApp “insider restock” that quotes your real cancelled order number
  • Voice calls that open with your postcode and a plush name
  • Fake refund portals asking for a card “because the original authorisation failed”

Pokémon Center will not need a card-security code to finish a CEVA investigation. CEVA will not ask you to mint a new PayPal invoice in Telegram. Open pokemoncenter.com yourself by typing it. Do not use a link in the suspicious message even if the address matches your last order.

What Pokémon Center and CEVA have said

Pokémon Center’s attested voice in this story is the customer email plus the UK-site delay banner. BleepingComputer had no reply from brand or media contacts on the cancellation logic.

CEVA’s earlier TechCrunch statement, from the Valve week, described a cyber incident impacting part of its European contract logistics operations, limited to eight warehouses, with other global systems unaffected. It said it activated security protocols and launched an investigation. That statement did not name Pokémon Center. The Pokémon Center email is how we know this brand was on the CEVA UK/DE path.

No public headcount for Pokémon Center’s cohort has been published. BreachHistory keeps recordsAffected 0 until an attested figure appears — the same discipline as the Valve row.

Industry context: shared 3PLs and fandom drops

Shared warehouses concentrate doorstep identity. One intrusion becomes Bol, Ajax, ING merch, Ace & Tate, Valve, and now Pokémon Center. The Dutch DPA’s “10 organisations” comment from mid-August already told you more brand letters were coming. This is one of them.

Fandom retail is a worse phishing surface than a generic fashion shop. Pokémon TCG drops sell out. Anniversary collections get screenshot and scalped. A leaked “you ordered X to this address” row is a social-engineering kit: urgency is built into the product. Hardware-wallet shipping leaks this summer (Trezor/ShipMonk, SafePal order tracking) taught the same lesson in a different aisle — purchase metadata is enough. Pokémon Center’s case is CEVA, not a plugin bug, but the user-facing risk is still “someone who knows what you bought will impersonate the store.”

Related catalog rows: CEVA hub, Valve, Bol, Ajax, Ace & Tate, ING NL.

Was I affected?

There is no public “search your order number” portal. The email is the notice. If you shopped PokemonCenter.com for UK or German delivery, used CEVA as the silent shipper, and received the cancellation-plus-incident mail, assume the five field types above. If you never ordered from that path, you are outside the attested extract.

Do not paste an order number into a Google result titled “Pokémon Center breach checker.” Do not send a photo of your packing slip to a Discord mod who “works CEVA IR.”

What you should do

  1. Read the official Pokémon Center email if you received one. Keep it. Match the order number to your own checkout history.
  2. Watch your original payment method for a cancellation reversal. Do not “re-pay” from SMS.
  3. Ignore delivery, customs, restock, and refund urgency by SMS, WhatsApp, Discord, or phone, even when the address and SKU match.
  4. Check order status only on pokemoncenter.com that you typed yourself, or the account email thread you already had before 17 August.
  5. Do not change a Nintendo Account password solely because of this CEVA incident unless you reused that password elsewhere or see unrelated login alerts. This notice is shipping PII, not Nintendo auth.
  6. Brief household members who might answer “Pokémon Center courier” calls, especially if a gift was going to a child.
  7. If an anniversary or TCG order died: assume scalpers will impersonate a second-chance drop. Official restocks happen on the site, not in DMs.
  8. Employees at Pokémon / CEVA partners: verify any “CEVA access reset” IT prompt out of band.

How this compares to Valve’s CEVA notice

Valve told European Steam hardware buyers: names, addresses, phones, emails, product type and price; no Steam passwords; do not change your Steam password because of CEVA; 90-day retention; access window 29 July–1 August. Pokémon Center told UK/DE merch buyers: names, addresses, phones, emails, order contents; no payment cards at CEVA; attack commencing 30 July; some orders cancelled. Same shipper, same week, same field class. Pokémon Center added cancellations and a fandom SKU list that Valve did not have to deal with.

If you are in both extracts — a Deck and a Pikachu plush in the same month — you get two brand-themed lure kits from one warehouse incident. That is the 3PL concentration problem in one household.

Canonical record and sources

Canonical BreachHistory page: 2026 Pokémon Center — CEVA Logistics UK/Germany shipping breach.

Sources: BleepingComputer, FreightWaves, Valve/CEVA coverage, TechCrunch CEVA.

For TCG groups and Discord mods

Community servers will fill with screenshots of the cancellation mail within hours. A clean script: CEVA shipper breach; UK/DE PokemonCenter.com shipping fields possibly exposed; cards not held by CEVA; some orders cancelled; no customs fees by SMS; official status only on the site you type; report fake restocks, do not collect order numbers “to check who’s affected.”

Collecting order numbers in a public Discord is how a helpful server becomes a second leak. Point people at their own email and this catalog page instead.

Physical security and porch risk

Address plus “expensive unreleased merch” is porch-pirate and courier-impersonation bait. If a parcel is still supposed to arrive despite the delay banner, use the tracking page you already had, not a new link. If the order was cancelled, there should not be a courier at the door asking you to “confirm the breach fee.”

Parents should tell kids not to answer “Pokémon warehouse” calls. The child who knows a drop is coming is exactly who a social engineer wants on the phone.

What remains unknown

Headcount, whether Pokémon Center’s retention matched Valve’s 90 days, why cancellations were required, whether UK ICO or German DPA filings will name a census, and whether Pokémon Center rows appear in the same dark-web retail packs already described for Bol. Those gaps do not block individual action. The email is enough to start.

BleepingComputer had no comment from the brand at publication. If Pokémon Center later posts a FAQ with a number, the catalog row should pick up that census. Until then, do not invent “millions of trainers.”

Reading the UK-site delay banner

A homepage delay warning is not a substitute for a GDPR-style individual notice, but it is a useful tell that fulfilment is still degraded more than two weeks after 30 July. If you placed a new UK order after the banner appeared, read the current shipping copy before you assume CEVA still holds a live copy of that new row. The attested incident window is late July. New orders may be a different warehouse path — or the same one, still limping. The email you did or did not get is the better signal for PII exposure than the banner alone.

Nintendo Account vs Pokémon Center account

Shoppers blur these. Pokémon Center ecommerce accounts are not the same as a Nintendo Account used for Switch Online. This CEVA incident, as described, is logistics PII for UK/DE merch orders. It is not a reason to panic-reset every Nintendo login. It is a reason to treat Pokémon Center-branded parcel messages as hostile until you verify on the store site.

If a message asks for a Nintendo Network ID, a Switch friend code, or a Pokémon HOME login “to validate your cancelled order,” that is a different steal. Hang up.

FAQ

Was my card stolen? Pokémon Center says CEVA does not have payment-card details.

Why was my anniversary order cancelled? The brand has not explained the cancellation logic. Watch for a refund on the original payment method. Do not pay a second invoice from a text.

I shop on the US site. Am I in this file? The published email names UK and Germany PokemonCenter.com fulfilment through CEVA. That is not a US-store notice. Still ignore copycat phishing.

Is this the same as the Valve Steam Deck leak? Same shipper, same late-July window, same class of shipping fields. Different brand, different SKUs, Pokémon Center also cancelled some orders.