A supplier breach reaches another consumer brand

Pokémon Center has told customers in the United Kingdom and Germany that CEVA Logistics, its delivery provider in those markets, suffered a cyberattack beginning on July 30, 2026. The incident is linked to the same disruption previously disclosed by Valve, whose European Steam hardware deliveries also rely on CEVA.

The development illustrates a persistent security problem in e-commerce: a retailer can protect its storefront, payment systems and customer accounts, yet still face a serious incident through a third party that receives data to store, pick, pack and deliver an order. Logistics providers hold information that is operationally necessary but highly useful to fraudsters when combined: names, addresses, email addresses, telephone numbers and details of a recent purchase.

For Pokémon Center, the incident concerns UK and German fulfilment rather than an intrusion into the retailer’s online shop itself. That distinction matters, but it does not eliminate risk for customers whose delivery records may have been affected.

What data may be involved

Pokémon Center said the information most likely exposed includes customers’ names, mailing addresses, phone numbers, email addresses and details of previous orders. It said payment information and Pokémon Center account information were not affected.

That closely resembles the information Valve described in notices sent to European buyers of Steam hardware. Valve said CEVA retained delivery-related records for up to 90 days after an order, and that potentially compromised data included the buyer’s name, address, country, phone number, Steam email address, and the type and price of purchased hardware. Valve said payment details, passwords, Steam Guard codes and other Steam account information were not involved.

The overlap supports the conclusion that CEVA’s systems, rather than the retailers’ principal customer-account platforms, were the common point of exposure. However, customers should not assume that every CEVA client, warehouse, order period or data field was affected in the same way. The publicly reported scope remains incomplete, and organisations are continuing to identify affected people and records.

Delays are part of the operational impact

The breach has had an operational as well as privacy impact. Pokémon Center’s UK support pages have warned that some orders are taking longer to process, dispatch and deliver. Reporting on the CEVA incident indicated that disruption affected eight European warehouses, creating delivery problems for a number of retail customers.

This is a reminder that warehouse systems are not simply back-office tools. They coordinate stock availability, order allocation, labels, carrier hand-offs and customer communications. When those systems are isolated during an investigation, retailers may be unable to confirm whether an order can be fulfilled, whether its address is accurate, or whether an item has left a facility. Order holds, delayed dispatches and cancellations can follow even when the retailer’s own website remains available.

For Pokémon Center customers, a delayed or cancelled order should therefore be treated as a fulfilment issue linked to the wider incident, not as evidence that a Pokémon Center account has necessarily been accessed.

The main immediate risk is targeted fraud

Delivery and order information can make phishing attempts substantially more convincing. A criminal who knows a customer’s name, address, email address and what they bought can send a message that appears to concern a delayed parcel, a replacement order, a customs charge or a refund. The goal may be to steal payment details, passwords or one-time authentication codes.

Affected customers should be particularly wary of unexpected messages that create urgency or request action outside the normal Pokémon Center or delivery-carrier process. Useful precautions include:

  • Do not use links in unexpected delivery, refund or account-security messages. Instead, visit the retailer or carrier through a saved bookmark or by entering the address independently.
  • Check order status through the Pokémon Center account or official order-lookup tools, rather than through a link in an email or text.
  • Never disclose passwords, payment-card details or multi-factor authentication codes to someone who contacts you unexpectedly.
  • Use a unique password for Pokémon Center and enable multi-factor authentication where it is available on important accounts, especially email.
  • Monitor bank and card statements, while recognising that the retailer says payment data was not affected by this incident.

Changing a password at Pokémon Center is a reasonable precaution for anyone concerned, particularly if it has been reused elsewhere. It is not, however, a substitute for protecting the email account connected to online shopping, which is often the route through which password resets and fraudulent order messages are delivered.

A test of third-party risk management

The incident puts attention on the data-sharing practices behind online retail. Retailers need to send fulfilment partners enough information to deliver goods, but limiting the data sent, reducing retention periods and separating client environments can constrain the harm from a compromise. Clear contractual security requirements, continuous supplier assessment and rehearsed incident-notification procedures are equally important.

For consumers, the practical lesson is that a data breach notice may arrive from a company they did not directly choose. The delivery network has become part of the digital supply chain, and personal data travels through it alongside the parcel.

Under European data-protection rules, organisations must assess whether a breach poses a risk to individuals and notify the relevant supervisory authority where required. When the risk is high, affected people must be informed without undue delay so they can take protective action. As the CEVA investigation continues, the quality and specificity of customer notifications will be central to reducing the likelihood of follow-on fraud.

Pokémon Center customers in the UK and Germany should rely on direct communications from the company, keep an eye on official support updates, and treat any unsolicited order-related message with heightened caution until the full scope of the breach is known.

Sources