Tuesday, August 25, 2026

Independent technology reporting and practical analysis

Manila ·
CYBERSECURITY

Independent reporting, useful context, and practical analysis.

Back to Technomalist
Cybersecurity / news

Pokémon Center UK customer data exposed in third-party logistics cyberattack

The official Pokémon merchandise store has notified UK and Germany customers that a cyberattack on logistics provider CEVA Logistics may have exposed names, addresses, phone numbers, emails, and order history.

Jiggly puff Angry
Jiggly puff Angry

Customers who recently ordered Pokémon merchandise from the official UK store may need to reorder after a cyberattack on the company’s logistics provider disrupted operations.

Pokémon Center, the official store for Pokémon merchandise in the UK, has emailed customers to alert them about a third-party cyberattack and its consequences, according to BleepingComputer, which obtained a copy of the message. The company told customers that some recent orders had to be cancelled due to an unforeseen fulfilment issue. A notice on the Pokémon Center website also says the company is experiencing delays affecting some orders for UK customers, with longer than usual processing, dispatch, and delivery times.

The attack struck CEVA Logistics, the vendor used by Pokémon Center to ship products from PokemonCenter.com for customers in the United Kingdom and Germany. In the customer email cited by the report, Pokémon Center said CEVA Logistics informed them that it was the victim of a cyberattack beginning on 30 July 2026.

The source article also notes that last week, an unnamed major shipping and logistics company disclosed a separate incident that forced it to shut down parts of its IT infrastructure and affected eight warehouses. Some of that company’s customers reported being affected, including Dutch retailers Bol and De Bijenkorf, and PC gaming company Valve. The article does not explicitly state whether this unnamed company is CEVA Logistics or whether the two incidents are the same.

According to Pokémon Center, the data most likely exposed in the incident includes customers’ full names, mailing addresses, phone numbers, email addresses, and details about what they previously ordered on the site. User accounts and payment details are reportedly safe.

The report says that, so far, around a dozen organizations are confirmed as having been affected by the breach. No threat actors have claimed responsibility for the attack at the time the article was published.

The source material does not specify the nature of the cyberattack, such as whether it involved ransomware, and no attribution to any specific group has been made public.

See an error? Read our corrections policy or email [email protected].

MORE FROM TECHNOMALIST

Continue reading

View all
Featured image for Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud
Cybersecurity

Researchers Show Expired Visa Contactless Cards Can Be Revived for Fraud

Philips LatteGo 4400 Series espresso machine on a kitchen counter.
Guides

Philips LatteGo 4400 espresso machine drops to AU$613 on Amazon Australia

Alice talks to Nora and Frank
Entertainment

How AI and assistive tools are helping disabled actors like Steve Way thrive on 'Furious'