Pokémon Center told customers in the United Kingdom and Germany that personal and order information was exposed after a cyberattack on CEVA Logistics, the third-party shipping provider handling deliveries in those countries. The attackers reportedly breached CEVA systems between late July and early August, exposing customer names, mailing addresses, phone numbers, email addresses, and order contents. Payment card data and Pokémon Center account information were not affected, as CEVA did not have access to that information.
The intrusion also disrupted fulfillment operations, causing shipping delays and the cancellation of some Pokémon Center orders. CEVA said the attack affected part of its European contract logistics environment and disrupted at least eight warehouses across Europe, with reports indicating other retailers were also impacted. Dutch data protection authorities and law enforcement are investigating, underscoring the wider supply-chain risk created when logistics providers are compromised.

See attribution, scope, and your downstream exposure.
7 events from the most recent confirmed update back to the earliest known activity.
On August 1, 2026, CEVA Logistics told affected customers that a cyber intrusion was impacting part of its European contract logistics operations. CEVA said the operational impact was contained to eight sites and no other global CEVA systems were affected.
Attackers breached CEVA Logistics servers between July 29 and August 1, 2026. The incident affected multiple European retailers and disrupted part of CEVA's European contract logistics operations.
CEVA Logistics informed affected parties that it was the victim of a cyberattack beginning on July 30, 2026. The attack impacted systems used to process delivery information for retail clients.
CEVA Logistics said the intrusion most likely began on July 29, 2026, preceding the broader disruption to its European logistics operations.
Dutch data protection authorities and other law enforcement agencies opened investigations into the CEVA Logistics incident. The company had not publicly disclosed the attack vector or attributed the intrusion to a threat actor.
Pokémon Center posted a UK website notice warning that some orders would take longer to process, dispatch, and deliver, and breach notification emails said some recent orders were canceled due to an unforeseen fulfillment issue. Customers reported both delays and cancellations tied to the CEVA incident.
Pokémon Center notified customers in the United Kingdom and Germany that their personal and order information may have been exposed through CEVA Logistics, its shipping provider in those countries. Exposed data may have included names, mailing addresses, phone numbers, email addresses, and order contents, while payment card data was not affected.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
5 references tracked. Mallory keeps watching after this page renders.
rhisac.org
Open sourcesecuritymagazine.com
Open sourceteiss.co.uk
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.