A recent supply-chain cyber incident involving CEVA Logistics, a third-party logistics provider used by Pokémon Center, has resulted in the potential exposure of customer and order-related information in the United Kingdom and Germany.
According to the reported notification, attackers compromised CEVA systems beginning July 30, 2026. The incident affected multiple European retailers and disrupted operations at several European warehouses. Pokémon Center customers may have had their names, physical addresses, phone numbers, email addresses, and order details exposed.
The incident demonstrates the security implications of third-party and supply-chain dependencies, particularly where external service providers process customer information and fulfillment data.
A separate historical breach involving Pokémon Negro in October 2016 exposed approximately 830,000 accounts, including email addresses, IP addresses, and plaintext passwords. While unrelated to the 2026 CEVA incident, the historical breach remains relevant from a credential-security and password-reuse perspective.
Incident Details
- Affected Organization: Pokémon Center
- Third-Party Provider: CEVA Logistics
- Parent Organization: CMA CGM Group
- Attack Type: Third-Party / Supply Chain Data Breach
- Attack Commencement: July 30, 2026
- Affected Regions: United Kingdom and Germany
- Potentially Affected Data: Customer and order information
- Payment Card Data: Reportedly not accessible to CEVA
- Operational Impact: Shipping delays and cancellation of some orders
Potentially Exposed Information
The following customer information may have been obtained by unauthorized parties:
- Full names
- Mailing addresses
- Phone numbers
- Email addresses
- Pokémon Center order details
- Information regarding ordered products
CEVA reportedly did not have access to customers' payment card information, reducing the risk of direct payment-card compromise from this particular incident.
Business and Security Impact
The incident demonstrates how compromise of a third-party logistics provider can indirectly affect organizations and their customers even when the primary organization's systems have not themselves been compromised.
Potential risks include:
- Phishing and Social Engineering: Exposed customer names, email addresses, addresses, and order details can enable highly convincing targeted phishing campaigns.
- Identity Fraud: Combination of personal information may increase the risk of impersonation attempts.
- Order Fraud: Knowledge of legitimate orders can be leveraged to create convincing fraudulent communications.
- Privacy Exposure: Physical addresses and contact information may be exposed to unauthorized parties.
- Supply Chain Risk: Organizations relying on third-party providers inherit additional cybersecurity and data-protection risks.
- Operational Disruption: The CEVA incident disrupted warehouse operations and contributed to shipping delays and order cancellations.
Historical Pokémon Negro Breach
In approximately October 2016, the Spanish Pokémon website Pokémon Negro reportedly suffered a separate data breach affecting approximately 830,000 accounts.
The compromised information reportedly included:
- Email addresses
- IP addresses
- Plaintext passwords
The incident is particularly significant because plaintext password exposure creates a high risk of credential reuse attacks when affected users use the same password on other services.
Recommended Security Actions
For Affected Customers
- Change passwords associated with any affected or potentially reused accounts.
- Do not reuse passwords across different services.
- Enable multi-factor authentication wherever supported.
- Monitor accounts for suspicious login activity.
- Be cautious of phishing emails referencing Pokémon Center orders, deliveries, refunds, or cancellations.
- Avoid clicking links in unexpected order-related messages.
- Monitor financial and online accounts for suspicious activity.
For Organizations
- Maintain a comprehensive third-party risk-management program.
- Assess security controls implemented by logistics and fulfillment providers.
- Minimize the amount of customer information shared with third parties.
- Apply data-retention and deletion controls to third-party systems.
- Require contractual breach-notification and incident-response obligations.
- Monitor for credential exposure and phishing campaigns following third-party breaches.
- Implement MFA and strong authentication controls.
- Conduct regular security assessments of critical suppliers and service providers.
Threat Intelligence Assessment
The 2026 Pokémon Center incident should be classified primarily as a Supply Chain / Third-Party Data Breach rather than a direct compromise of Pokémon Center infrastructure based on the available information.
The exposure of customer contact and order information creates a secondary threat of targeted phishing, social engineering, impersonation, and fraud. Organizations should monitor for malicious campaigns impersonating Pokémon Center, CEVA Logistics, delivery providers, or customer-support personnel.
The historical Pokémon Negro breach should additionally be considered a credential exposure event, particularly because plaintext passwords were reportedly disclosed. Organizations should monitor authentication telemetry for credential-stuffing or password-reuse activity involving potentially exposed accounts.
Key Takeaways
- CEVA Logistics was compromised in a cyberattack beginning July 30, 2026.
- Pokémon Center customers in the UK and Germany may have had personal and order information exposed.
- Payment-card information was reportedly not accessible to CEVA.
- The incident caused operational disruption, including shipping delays and some order cancellations.
- The event highlights the importance of third-party and supply-chain security controls.
- A separate 2016 Pokémon Negro breach exposed approximately 830,000 accounts and plaintext passwords.
- Exposed customer information should be treated as a potential enabler for targeted phishing and social-engineering attacks.