Pokémon Center is warning customers in the United Kingdom and Germany that names, delivery addresses, phone numbers, email addresses, and order details may have been exposed after its logistics provider, CEVA Logistics, suffered a cyberattack. The immediate risk is not a Pokémon account takeover or payment-card fraud based on this incident alone; it is highly convincing delivery phishing aimed at people whose real purchases, addresses, and contact details may now be in criminal hands.

The notice, reported by BleepingComputer, applies to orders submitted through PokemonCenter.com and shipped by CEVA in the UK and Germany. Pokémon Center says CEVA does not receive customers’ payment-card details, and that information beyond the delivery and order data supplied to the carrier was not affected. Those are important boundaries, but they should not be mistaken for a clean outcome: an attacker who knows what a person ordered and where it was meant to arrive has enough material to impersonate a retailer, courier, or customer-support agent far more effectively than in an ordinary spam campaign.

This is also not an isolated Pokémon Center incident. TechCrunch reported earlier this month that the CEVA breach affected multiple European retail customers, while Valve separately notified some European Steam hardware customers that delivery data held by CEVA was likely compromised. For Windows and PC users, the overlap is a reminder that security exposure increasingly sits outside the store, launcher, or platform where an order was placed. A company can protect account passwords and card data while a fulfillment partner still holds the personal information most useful for a doorstep scam.

A cyberpunk phishing scam targets package delivery, shown by a hooked email, parcel, smartphone, and warning shield.CEVA’s breach created a shared retail exposure​

CEVA Logistics is a major France-headquartered contract-logistics company and a subsidiary of CMA CGM. It handles warehousing and shipping for retailers that need to get physical goods from a distribution center to a customer’s home. That role requires access to a tightly focused but valuable bundle of information: recipient identity, address, contact details, order contents, and shipping status.

According to CEVA’s statement to TechCrunch, it confirmed on August 1 that a cyber intrusion was affecting part of its European contract-logistics operations. The company said the operational impact was limited to eight warehouses and that other CEVA systems globally were not affected. It also said it activated security procedures and was investigating with authorities.

The timing is less tidy in customer notices. Valve told affected Steam hardware buyers that the attack occurred between July 29 and August 1, while Pokémon Center’s notification says CEVA reported a cyberattack beginning on July 30. Neither account necessarily contradicts CEVA’s August 1 confirmation date: an intrusion can begin before a company identifies it, and different affected systems may have separate evidence trails. But the distinction should be recorded rather than blurred. CEVA has publicly described when it confirmed the intrusion, while its retail customers have described when they believe attacker activity occurred.

CEVA has not publicly disclosed the number of records involved, the entry point used by the attackers, whether data was exfiltrated from every affected client environment, or whether the company received a ransom demand. Those omissions matter for incident response professionals assessing the event. “Limited to eight warehouses” describes an operational scope, not the number of retailers, orders, or people caught within those sites’ systems.

For Pokémon Center customers, the practical point is simpler: the data may have left the retailer’s direct control after it was shared for fulfilment. The same model affected Valve’s European hardware buyers, whose delivery records were retained by CEVA for up to 90 days after purchase. Pokémon Center has not publicly stated a comparable retention window, affected order-date range, or number of UK and German customers notified.

Order cancellations have made the breach visible​

Pokémon Center’s emails have not merely warned about the data exposure. Customers have also reported canceled orders, including orders linked to 30th-anniversary merchandise and other products. Pokémon Center’s UK storefront has separately posted a notice warning that some orders are taking longer than usual to process, dispatch, and deliver.

The cancellation reports create a second problem for customers: they make a fraud attempt more believable. A message saying “your canceled Pokémon Center order can be restored,” “confirm your address for a replacement shipment,” or “pay a redelivery fee to avoid cancellation” is especially credible when real orders are delayed or canceled at the same time. Attackers do not need access to a Pokémon account to run that scheme; accurate name, order, address, and item information can do most of the social-engineering work.

BleepingComputer reported that Pokémon Center had not explained why the event required cancellations rather than ordinary delays. That unanswered question is material. A warehouse disruption can delay a shipment; canceling an order can result from lost fulfillment status, inventory reconciliation problems, concerns about the integrity of dispatch data, or a retailer’s effort to halt affected workflows. There is no public evidence yet showing which explanation applies here.

Customers should therefore resist filling in the blanks themselves. A canceled order does not prove that an attacker altered it, stole it, or gained access to the customer’s Pokémon account. Conversely, a cancellation does not make an unsolicited recovery message legitimate. The only safe way to check an order’s status is to enter the Pokémon Center site directly through a saved bookmark or manually typed address, then review the order history there.

What was exposed is enough for targeted fraud​

Pokémon Center says the potentially obtained data includes a customer’s name, mailing address, phone number, email address, and details of PokemonCenter.com orders. Payment card data was not provided to CEVA, according to Pokémon Center, and the company says other customer and order information was unaffected.

That exclusion narrows the immediate technical response. There is no stated basis for rushing to replace a payment card solely because of this breach, and there is no indication that Pokémon account passwords or login credentials were exposed through CEVA. Password reuse is always a separate risk, but this incident does not currently establish a password leak.

The disclosed delivery data is still sensitive because it enables attacks that can survive normal scam filters. A criminal can send a text that includes the correct street, refers to a specific item, and claims a delivery is held because of the recent logistics disruption. They may pose as Pokémon Center, Royal Mail, DHL, DPD, a customs service, a bank’s fraud department, or even a support agent offering an expedited replacement.

For PC enthusiasts, Valve’s handling of the same CEVA event offers the clearest model of the threat. Valve explicitly warned Steam hardware buyers to expect fake emails, texts, or calls that reference their real hardware orders. The Pokémon Center data set described in its notification has the same elements needed for that kind of pretext: personal contact details plus product and transaction context.

A legitimate carrier or retailer may send an order update, but recipients should treat unexpected requests for a payment, password, one-time code, or account-login confirmation as hostile until proven otherwise. The safest approach is to open the retailer’s or carrier’s app independently, not to follow a message link, scan a QR code from an email, or call a telephone number supplied in a surprise text.

Sensible steps for affected UK and German customers​

People who received a Pokémon Center breach notification should keep the email for their records, but they should not use its links to manage an order. The notification itself may be genuine, yet future attackers can copy its wording and branding almost exactly.

A short response plan is appropriate:

  • Review recent Pokémon Center orders by signing in directly at PokemonCenter.com, and save screenshots of any cancellation, refund, or delivery-status change.
  • Watch for emails, texts, and calls that mention a Pokémon Center purchase, an exact delivery address, an anniversary item, a replacement shipment, or a customs or redelivery payment.
  • Do not provide a password, payment card number, banking information, or authentication code in response to an order-related message or phone call.
  • Use a unique password and multi-factor authentication on the email account associated with the purchase, because control of that inbox can turn a shipping-data breach into a broader account-recovery risk.
  • Check payment statements as a normal precaution, but distinguish suspicious card activity from the delivery-data exposure actually described by Pokémon Center.
  • Report impersonation messages through the relevant courier or retailer’s established reporting channel, and report fraud attempts to the appropriate national consumer or cybercrime authority.

Enterprise administrators should recognize the same lesson at a different scale. Third-party logistics, returns processing, warranty replacement, and device lifecycle vendors frequently hold employee addresses, asset descriptions, serial numbers, work email addresses, and delivery schedules. Those details can seed credential phishing against a company’s staff even when the enterprise’s own identity systems were never breached. Vendor-risk reviews should treat fulfillment data as a phishing-enablement data set, not as harmless operational metadata.

Pokémon Center has told UK and German customers what data may have been involved, but key facts remain undisclosed: the number of people affected, the full order-date range, the basis for cancellations, and whether CEVA has determined exactly which records attackers took. Until those answers emerge, the concrete consequence is straightforward: every unexpected order, delivery, refund, or replacement message tied to Pokémon Center deserves verification through an independently opened official account or carrier channel.