
Pokémon Center customers warned after logistics cyberattack
Customers using the official Pokémon merchandise store in the United Kingdom and Germany have been affected by a data breach involving CEVA Logistics, the third-party provider responsible for shipping Pokémon Center orders.
The incident began on 30 July 2026. Some orders have reportedly been cancelled, while UK customers have been warned that processing, dispatch and delivery may take longer than usual.

What information may have been exposed?
Pokémon Center has told affected customers that the stolen information may include:
- Full names
- Mailing addresses
- Phone numbers
- Email addresses
- Order information
In an email sent to customers, the company apologised and explained that CEVA Logistics had been the victim of a cyberattack. The message also confirmed that at least some recent orders were cancelled because of an unexpected fulfilment problem.
“We’re sorry to inform you that we have had to cancel your recent order [order number] due to an unforeseen fulfillment issue.”
“CEVA Logistics, the vendor Pokémon Center utilises to ship product from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026.”
Further details about the affected customer information and cancelled orders are available in this security report.

A wider European supply-chain breach
CEVA Logistics operates under CMA CGM, described in the source material as the world’s third-largest container shipping corporation. The incident reportedly reached eight warehouses across Europe and affected businesses beyond the Pokémon merchandise operation.
Those named as affected include Dutch retailer Bol, football club Ajax, ING Bank and eyewear company Ace & Tate. The breach is part of a broader pattern of attacks targeting global cargo and logistics systems, where criminals have sometimes redirected shipments to criminal organisations.
Coverage of the wider incident describes it as impacting a wide range of companies.

Why the timing matters for Pokémon fans
The disruption arrives during Pokémon Center’s 30th-anniversary campaign. More than 100 themed products were listed as part of the celebration, including posters, keychains, clothing and other merchandise.
For collectors and arcade fans following licensed gaming products, the incident is a reminder that an order can depend on several linked businesses rather than the retailer alone. Our arcade news and features provide more coverage of developments across gaming and the arcade industry.

What affected customers should watch for
Customers in the UK and Germany should be alert for suspicious messages referring to Pokémon Center purchases, delivery problems or order cancellations. Since names, contact details and order information may have been exposed, unsolicited emails or phone calls could appear convincing.
Do not provide passwords, payment details or one-time security codes in response to an unexpected message. Check order information through the official account or retailer website, and contact the relevant support team using details obtained independently.

Related gaming breaches
The same CEVA incident also affected Valve customers, prompting warnings about scam emails concerning Steam Machine and Steam Controller purchases. Retailers and buyers can also reduce risk by reviewing account security and keeping records of legitimate orders.


Anyone considering a home arcade setup can explore RETROCADE’s arcade machine buying guide or browse the available arcade machines.


Leave a Reply