Pokemon Center is notifying customers in the United Kingdom and Germany that their personal and order information was exposed in a data breach — not through a direct attack on Pokemon Center itself, but via a compromise of CEVA Logistics, a third-party logistics provider handling order fulfillment for the popular merchandise retailer.
The breach is the latest example of supply chain risk translating directly into customer data exposure, with some affected customers having their orders outright cancelled as a result of the incident.
What Happened
According to notifications sent to affected customers and reporting by BleepingComputer, hackers targeted CEVA Logistics, a global logistics and supply chain management company used by Pokemon Center to handle order processing and fulfillment in Europe. The attackers were able to access order and customer data held by CEVA, which included information passed from Pokemon Center as part of the fulfillment process.
Pokemon Center has confirmed the breach affects customers in the UK and Germany — the two European markets where CEVA Logistics was handling their logistics operations. Customers in other regions, including North America and Japan, do not appear to have been affected.
What Data Was Exposed
The breach exposed information that Pokemon Center provided to CEVA Logistics as part of fulfilling customer orders. This typically includes:
| Data Type | Status |
|---|---|
| Full name | Exposed |
| Delivery address | Exposed |
| Email address | Exposed |
| Order details and items purchased | Exposed |
| Order value and payment method type | Likely exposed |
| Full payment card numbers | Not exposed (not shared with logistics providers) |
Pokemon Center emphasized that full payment card data was not shared with CEVA Logistics and is therefore not at risk from this breach. However, the combination of name, address, email, and detailed order information is sufficient for targeted phishing and social engineering attacks.
Order Cancellations
In a notable response measure, Pokemon Center has cancelled some affected customer orders. The company has not specified the precise criteria for cancellations — it may relate to orders that were in-transit or undelivered at the time of the breach, where fulfilment details were already in CEVA's systems.
Affected customers whose orders were cancelled will receive refunds. Pokemon Center has advised customers to check their email for notifications and to reorder directly through the official Pokemon Center website.
Third-Party Risk: A Growing Problem
This incident follows a familiar pattern in retail and e-commerce cybersecurity. Major brands increasingly rely on networks of third-party vendors — logistics providers, marketing platforms, payment processors, review systems — each holding a slice of customer data. Attackers have learned that targeting these vendors, which may have weaker security postures than the primary brand, is an effective path to high-value customer records at scale.
Recent comparable incidents include:
- Snowflake (2024): Dozens of major brands' customer data accessed through the cloud data platform
- MOVEit (2023): Hundreds of organizations exposed via a managed file transfer platform
- Change Healthcare (2024): US healthcare records impacted via a payments processor
In each case, the end customer's data was exposed not because the brand they trusted was breached directly, but because a vendor in the supply chain was.
What Affected Customers Should Do
If you received a notification from Pokemon Center about this breach, take the following steps:
-
Watch for phishing: Expect emails, texts, or calls claiming to be from Pokemon Center, CEVA Logistics, or couriers. Scammers will use your real order and address details to make these convincing.
-
Do not click links in unsolicited emails: Navigate directly to
pokemoncenter.comto check your order status rather than using links in notification emails. -
Verify your refund: If your order was cancelled, confirm the refund through your bank or card statement rather than through any link provided in an email.
-
Be alert to address-based fraud: With your delivery address exposed, watch for unexpected packages, mail redirection scams, or attempts to redirect deliveries on your behalf.
-
Report suspicious contact: Report any phishing attempts or scam calls to Action Fraud (UK) or the Bundesnetzagentur (Germany).
GDPR Implications
Both the UK (UK GDPR, post-Brexit) and Germany (GDPR under EU law) impose strict requirements on data controllers — including brand retailers like Pokemon Center — even when the breach occurs at a data processor (like CEVA Logistics).
Under GDPR Article 28, data processors must process data only on documented instructions from the controller and implement appropriate technical and organizational security measures. Pokemon Center, as the data controller, bears responsibility for ensuring CEVA met these requirements.
Pokemon Center must:
- Notify the UK ICO within 72 hours of becoming aware of the breach (if it poses risk to individuals)
- Notify the German DPA (BSI/relevant Landesbehörde) under equivalent timelines
- Notify affected individuals if the breach poses a high risk to their rights and freedoms
The company appears to be fulfilling its customer notification obligations. Whether it met the regulatory notification timelines and whether CEVA's security measures were contractually and technically adequate will likely be examined by regulators.
For Security and Risk Professionals
This breach is a reminder of several critical vendor risk management principles:
Data Minimization
Only share with vendors the data they strictly need. A logistics provider needs a delivery address and contact details — detailed purchase history or account credentials should not be included.
Vendor Security Assessments
Conduct periodic security assessments of logistics providers and other vendors who handle personal data. Logistics companies often operate at scale with thin IT margins, making them attractive targets and potentially weaker defenders.
Contractual Data Protection Requirements
Ensure data processing agreements (DPAs) under GDPR Article 28 include specific security standards, breach notification timelines to the controller, and audit rights.
Incident Response Coordination
Establish clear breach response runbooks that cover third-party incidents — including who is responsible for notifying regulators and customers when the breach occurs at a vendor, not internally.
Source: BleepingComputer