Pokémon Center is informing customers in the United Kingdom and Germany that some of their personal information may have been exposed following a cyberattack against CEVA Logistics, the third-party company responsible for fulfilling and shipping orders in those markets. The incident has also disrupted deliveries, with some customers reporting that their orders were canceled.
The compromised systems belonged to CEVA Logistics rather than Pokémon Center itself. However, CEVA held customer information that Pokémon Center provided so that orders placed through PokemonCenter.com could be prepared and delivered. This meant attackers potentially gained access to customer records despite not directly compromising Pokémon Center’s systems.
CEVA suffered a cyberattack that affected parts of its European operations between July 29 and August 1. The company operates a large international logistics network and provides warehousing and transportation services for numerous businesses, meaning the consequences of the incident have extended beyond a single retailer. Several European warehouses were disrupted, contributing to shipment delays.
According to notifications sent to affected Pokémon Center customers, the attack began on July 30. The potentially compromised information includes customers’ full names, postal addresses, telephone numbers, and email addresses. Information identifying the products contained in individual PokemonCenter.com orders may also have been accessed.
Pokémon Center said other customer and order information was not affected. Importantly, CEVA does not have access to customers’ payment card information, so card details are not among the data identified as potentially exposed through the logistics provider.
The breach has created problems beyond the exposure of customer information. Pokémon Center has displayed a notice on its UK store warning shoppers that some orders are experiencing delays and could require additional time for processing, dispatch and delivery.
Some customers have instead received emails telling them their purchases were canceled because of an unexpected fulfillment problem. The cancellation messages also contained information about the CEVA security incident. It remains unclear why particular purchases needed to be canceled rather than simply delayed.
Reports initially centered on orders involving Pokémon’s anticipated 30th anniversary merchandise, but customers have also reported cancellations involving unrelated products. A Reddit user, for example, reported that an order for a Ghost Chateau Cyndaquil keyring had been canceled, with another customer saying they had received a similar notification.
Pokémon Center has not publicly provided a figure for the number of customers affected. It is also unclear how many of the potentially exposed records belong to customers in the UK compared with Germany.
The CEVA incident has affected customers of other companies as well. Valve previously notified European customers who purchased Steam hardware that information held by the same logistics provider had been compromised. Those records included contact and delivery information associated with customer orders.
The two incidents illustrate how a breach at a logistics company can expose information belonging to customers of businesses whose own systems were not necessarily compromised. Retailers routinely provide fulfillment partners with the names, addresses, and contact details required to deliver purchases, placing customer information within another organization’s infrastructure.
For Pokémon Center customers, the confirmed concern is therefore limited to information shared with CEVA for order fulfillment. Payment card information was not available to the logistics provider, while the precise number of affected customers and the full reason behind the reported order cancellations have not yet been established.