Pokémon Center Customer Data Exposed in Third-Party Breach via CEVA Logistics
The Pokémon Center, the official retailer for Pokémon merchandise, confirmed a data breach stemming from a cyberattack on its logistics partner, CEVA Logistics. The incident, which occurred on July 30, exposed customer order details including names, email addresses, phone numbers, and physical addresses for orders shipped to the United Kingdom and Germany.
While the Pokémon Center’s systems were not directly compromised, the breach disrupted operations, leading to delivery delays and cancellations for some customers. Payment card information was reportedly not affected. CEVA Logistics, which handles shipping for the retailer, notified the Pokémon Center of the attack, though the full scope of the breach and its impact on other clients remains unclear.
The incident underscores the growing risk of third-party supply chain attacks, where vulnerabilities in partner networks can expose sensitive customer data. No further details on the attack’s origin or the number of affected individuals have been disclosed.
CEVA Logistics cybersecurity rating report: https://www.rankiteo.com/company/ceva-logistics
The Pokémon Company International cybersecurity rating report: https://www.rankiteo.com/company/pokemon
"id": "CEVPOK1787070452",
"linkid": "ceva-logistics, pokemon",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'E-commerce, Merchandise',
'location': 'Global (primarily United Kingdom and '
'Germany)',
'name': 'Pokémon Center',
'type': 'Retailer'},
{'industry': 'Logistics, Supply Chain',
'location': 'Global',
'name': 'CEVA Logistics',
'type': 'Logistics Provider'}],
'attack_vector': 'Third-Party Supply Chain Attack',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'Personally Identifiable Information '
'(PII)',
'type_of_data_compromised': ['Names',
'Email addresses',
'Phone numbers',
'Physical addresses']},
'date_detected': '2024-07-30',
'description': 'The Pokémon Center, the official retailer for Pokémon '
'merchandise, confirmed a data breach stemming from a '
'cyberattack on its logistics partner, CEVA Logistics. The '
'incident exposed customer order details including names, '
'email addresses, phone numbers, and physical addresses for '
'orders shipped to the United Kingdom and Germany. Payment '
'card information was reportedly not affected, but the breach '
'disrupted operations, leading to delivery delays and '
'cancellations for some customers.',
'impact': {'data_compromised': 'Customer order details (names, email '
'addresses, phone numbers, physical addresses)',
'identity_theft_risk': 'Potential risk due to exposure of '
'personally identifiable information',
'operational_impact': 'Delivery delays and cancellations',
'payment_information_risk': 'None (payment card information not '
'affected)',
'systems_affected': 'CEVA Logistics systems (third-party logistics '
'partner)'},
'lessons_learned': 'The incident underscores the growing risk of third-party '
'supply chain attacks, where vulnerabilities in partner '
'networks can expose sensitive customer data.',
'references': [{'source': 'Pokémon Center Statement'}],
'title': 'Pokémon Center Customer Data Exposed in Third-Party Breach via CEVA '
'Logistics',
'type': 'Data Breach'}