Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2401+ Articles
159+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Pokemon Center Data Breach Exposes Customer Info, Cancels Some Orders
Pokemon Center Data Breach Exposes Customer Info, Cancels Some Orders
NEWS

Pokemon Center Data Breach Exposes Customer Info, Cancels Some Orders

Pokemon Center is notifying UK and Germany customers of a third-party breach at logistics provider CEVA Logistics that exposed personal and order data.

Dylan H.

News Desk

August 17, 2026
5 min read

Pokemon Center is notifying customers in the United Kingdom and Germany that their personal and order information was exposed in a data breach — not through a direct attack on Pokemon Center itself, but via a compromise of CEVA Logistics, a third-party logistics provider handling order fulfillment for the popular merchandise retailer.

The breach is the latest example of supply chain risk translating directly into customer data exposure, with some affected customers having their orders outright cancelled as a result of the incident.

What Happened

According to notifications sent to affected customers and reporting by BleepingComputer, hackers targeted CEVA Logistics, a global logistics and supply chain management company used by Pokemon Center to handle order processing and fulfillment in Europe. The attackers were able to access order and customer data held by CEVA, which included information passed from Pokemon Center as part of the fulfillment process.

Pokemon Center has confirmed the breach affects customers in the UK and Germany — the two European markets where CEVA Logistics was handling their logistics operations. Customers in other regions, including North America and Japan, do not appear to have been affected.

What Data Was Exposed

The breach exposed information that Pokemon Center provided to CEVA Logistics as part of fulfilling customer orders. This typically includes:

Data TypeStatus
Full nameExposed
Delivery addressExposed
Email addressExposed
Order details and items purchasedExposed
Order value and payment method typeLikely exposed
Full payment card numbersNot exposed (not shared with logistics providers)

Pokemon Center emphasized that full payment card data was not shared with CEVA Logistics and is therefore not at risk from this breach. However, the combination of name, address, email, and detailed order information is sufficient for targeted phishing and social engineering attacks.

Order Cancellations

In a notable response measure, Pokemon Center has cancelled some affected customer orders. The company has not specified the precise criteria for cancellations — it may relate to orders that were in-transit or undelivered at the time of the breach, where fulfilment details were already in CEVA's systems.

Affected customers whose orders were cancelled will receive refunds. Pokemon Center has advised customers to check their email for notifications and to reorder directly through the official Pokemon Center website.

Third-Party Risk: A Growing Problem

This incident follows a familiar pattern in retail and e-commerce cybersecurity. Major brands increasingly rely on networks of third-party vendors — logistics providers, marketing platforms, payment processors, review systems — each holding a slice of customer data. Attackers have learned that targeting these vendors, which may have weaker security postures than the primary brand, is an effective path to high-value customer records at scale.

Recent comparable incidents include:

  • Snowflake (2024): Dozens of major brands' customer data accessed through the cloud data platform
  • MOVEit (2023): Hundreds of organizations exposed via a managed file transfer platform
  • Change Healthcare (2024): US healthcare records impacted via a payments processor

In each case, the end customer's data was exposed not because the brand they trusted was breached directly, but because a vendor in the supply chain was.

What Affected Customers Should Do

If you received a notification from Pokemon Center about this breach, take the following steps:

  1. Watch for phishing: Expect emails, texts, or calls claiming to be from Pokemon Center, CEVA Logistics, or couriers. Scammers will use your real order and address details to make these convincing.

  2. Do not click links in unsolicited emails: Navigate directly to pokemoncenter.com to check your order status rather than using links in notification emails.

  3. Verify your refund: If your order was cancelled, confirm the refund through your bank or card statement rather than through any link provided in an email.

  4. Be alert to address-based fraud: With your delivery address exposed, watch for unexpected packages, mail redirection scams, or attempts to redirect deliveries on your behalf.

  5. Report suspicious contact: Report any phishing attempts or scam calls to Action Fraud (UK) or the Bundesnetzagentur (Germany).

GDPR Implications

Both the UK (UK GDPR, post-Brexit) and Germany (GDPR under EU law) impose strict requirements on data controllers — including brand retailers like Pokemon Center — even when the breach occurs at a data processor (like CEVA Logistics).

Under GDPR Article 28, data processors must process data only on documented instructions from the controller and implement appropriate technical and organizational security measures. Pokemon Center, as the data controller, bears responsibility for ensuring CEVA met these requirements.

Pokemon Center must:

  • Notify the UK ICO within 72 hours of becoming aware of the breach (if it poses risk to individuals)
  • Notify the German DPA (BSI/relevant Landesbehörde) under equivalent timelines
  • Notify affected individuals if the breach poses a high risk to their rights and freedoms

The company appears to be fulfilling its customer notification obligations. Whether it met the regulatory notification timelines and whether CEVA's security measures were contractually and technically adequate will likely be examined by regulators.

For Security and Risk Professionals

This breach is a reminder of several critical vendor risk management principles:

Data Minimization

Only share with vendors the data they strictly need. A logistics provider needs a delivery address and contact details — detailed purchase history or account credentials should not be included.

Vendor Security Assessments

Conduct periodic security assessments of logistics providers and other vendors who handle personal data. Logistics companies often operate at scale with thin IT margins, making them attractive targets and potentially weaker defenders.

Contractual Data Protection Requirements

Ensure data processing agreements (DPAs) under GDPR Article 28 include specific security standards, breach notification timelines to the controller, and audit rights.

Incident Response Coordination

Establish clear breach response runbooks that cover third-party incidents — including who is responsible for notifying regulators and customers when the breach occurs at a vendor, not internally.


Source: BleepingComputer

#Data Breach#Supply Chain#Retail#GDPR#Third Party Risk

Related Articles

Lidl Discloses Online Shop Breach After Service Provider Hack

German supermarket giant Lidl has notified customers in Germany, Belgium, and the Netherlands that personal data was stolen following a breach at one of...

5 min read

Origin Energy Data Breach Affects 900,000 Australians

Australian energy giant Origin Energy confirmed a data breach exposing the personal and partial financial information of approximately 900,000 current and former customers, after a hacker exploited a third-party customer management platform and used credentials from a terminated employee.

4 min read

Poland Probes MyDr Healthcare Software Breach Potentially Affecting 19 Million

Polish authorities are investigating a breach at healthcare software firm MyDr that may have exposed personal data of up to 19 million patients.

5 min read
Back to all News