
Customers who recently ordered Pokémon merchandise from the official UK store may need to reorder after a cyberattack on the company’s logistics provider disrupted operations.
Pokémon Center, the official store for Pokémon merchandise in the UK, has emailed customers to alert them about a third-party cyberattack and its consequences, according to BleepingComputer, which obtained a copy of the message. The company told customers that some recent orders had to be cancelled due to an unforeseen fulfilment issue. A notice on the Pokémon Center website also says the company is experiencing delays affecting some orders for UK customers, with longer than usual processing, dispatch, and delivery times.
The attack struck CEVA Logistics, the vendor used by Pokémon Center to ship products from PokemonCenter.com for customers in the United Kingdom and Germany. In the customer email cited by the report, Pokémon Center said CEVA Logistics informed them that it was the victim of a cyberattack beginning on 30 July 2026.
The source article also notes that last week, an unnamed major shipping and logistics company disclosed a separate incident that forced it to shut down parts of its IT infrastructure and affected eight warehouses. Some of that company’s customers reported being affected, including Dutch retailers Bol and De Bijenkorf, and PC gaming company Valve. The article does not explicitly state whether this unnamed company is CEVA Logistics or whether the two incidents are the same.
According to Pokémon Center, the data most likely exposed in the incident includes customers’ full names, mailing addresses, phone numbers, email addresses, and details about what they previously ordered on the site. User accounts and payment details are reportedly safe.
The report says that, so far, around a dozen organizations are confirmed as having been affected by the breach. No threat actors have claimed responsibility for the attack at the time the article was published.
The source material does not specify the nature of the cyberattack, such as whether it involved ransomware, and no attribution to any specific group has been made public.
See an error? Read our corrections policy or email [email protected].
TECHNOMALIST

