A cyberattack on shipping vendor CEVA Logistics exposed names, addresses, phone numbers and order details. Payment cards and logins were not touched. Some orders have been cancelled outright.
Pokémon Center is notifying customers in the United Kingdom and Germany that their personal information was exposed in a breach at a third-party shipping vendor.
The attack hit CEVA Logistics, which handles fulfilment for PokemonCenter.com orders in both countries. Pokémon Center’s own website and systems were not compromised.
The company says CEVA informed it of a cyberattack that began on 30 July 2026.
What was exposed and what wasn’t
Exposed: full names, postal addresses, phone numbers, email addresses, and details of Pokémon Center orders including purchase history.
Not exposed: payment card details and login credentials. CEVA never had access to either, so neither was in the breached systems.
That distinction is real and it should lower the temperature. Nobody’s card is at risk here.
What remains at risk is targeted phishing. Someone holding a real name, a real address, and a real record of what a customer ordered can write a very convincing message about a delivery problem. Treat any unexpected email or text about a Pokémon Center order with suspicion, and go to the site directly rather than through a link.
Some orders were cancelled
Pokémon Center has cancelled an undisclosed number of pending orders as a result.
The notification email has drawn attention for how it is written. It opens by apologising for cancelling the customer’s recent order due to what it calls an unforeseen fulfilment issue, and only afterwards explains that the cause was a cyberattack that may have exposed their information.
Leading with the inconvenience and burying the breach is a choice. It is not the order most people would want that email in.
How big the CEVA attack was
CEVA is not a small vendor. It is a subsidiary of the CMA CGM Group, the world’s third-largest shipping company, and it operates around 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenue in 2025.
Attackers were in its servers between 29 July and 1 August. CEVA told customers the operational impact was contained to eight sites in its European contract logistics operations and that no other systems globally were affected.
The customer fallout has been considerably wider than eight sites suggests. Reporting has tied the same breach to Valve, Dutch retailers bol and De Bijenkorf, the bank ING, football club Ajax, and eyewear retailer Ace & Tate. Valve told Steam users that passwords and payment details were not exposed, for the same reason Pokémon Center gave.
Dutch data protection authorities and other agencies are investigating.
The part that keeps repeating
None of these companies were hacked. One shipping vendor was.
Muhammad Yahya Patel, a cybersecurity advisor at Huntress, put the lesson for the industry plainly: third-party risk programmes need to cover logistics, fulfilment, and operational partners with the same rigour applied to technology vendors.
Anyone in the UK or Germany who ordered from Pokémon Center in July should assume their delivery details are out there and read their inbox accordingly.
Article compiled and edited by Derek Gibbs (entertainment editor) and the Clownfish TV newsroom.
D/REZZED is part of Clownfish TV. For more news, views, and rants on gaming, tech, and pop culture, subscribe at clownfishtv.com. Watch the show on YouTube at @ClownfishTV where new episodes drop daily. Subscribe to the Clownfish TV podcast on Apple Podcasts, Spotify, iHeart, and wherever else you get your podcasts.
Hat Tips:
BleepingComputer (August 17, 2026), the original report, the notification email text, and the CEVA corporate figures
Cybernews (August 19, 2026), the full list of affected retailers and the confirmation on payment data
Forbes (August 18, 2026), Davey Winder’s reporting including the Huntress comment


