Pokémon Center and CEVA Logistics: Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Pokémon Center and CEVA Logistics: Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Pokémon Center Customer Data Exposed in Third-Party Breach via CEVA Logistics

The Pokémon Center, the official retailer for Pokémon merchandise, confirmed a data breach stemming from a cyberattack on its logistics partner, CEVA Logistics. The incident, which occurred on July 30, exposed customer order details including names, email addresses, phone numbers, and physical addresses for orders shipped to the United Kingdom and Germany.

While the Pokémon Center’s systems were not directly compromised, the breach disrupted operations, leading to delivery delays and cancellations for some customers. Payment card information was reportedly not affected. CEVA Logistics, which handles shipping for the retailer, notified the Pokémon Center of the attack, though the full scope of the breach and its impact on other clients remains unclear.

The incident underscores the growing risk of third-party supply chain attacks, where vulnerabilities in partner networks can expose sensitive customer data. No further details on the attack’s origin or the number of affected individuals have been disclosed.

Source: https://www.securitymagazine.com/articles/102495-third-party-breach-exposes-pokemon-center-customer-data

CEVA Logistics cybersecurity rating report: https://www.rankiteo.com/company/ceva-logistics

The Pokémon Company International cybersecurity rating report: https://www.rankiteo.com/company/pokemon

"id": "CEVPOK1787070452",
"linkid": "ceva-logistics, pokemon",
"type": "Breach",
"date": "7/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'E-commerce, Merchandise',
                        'location': 'Global (primarily United Kingdom and '
                                    'Germany)',
                        'name': 'Pokémon Center',
                        'type': 'Retailer'},
                       {'industry': 'Logistics, Supply Chain',
                        'location': 'Global',
                        'name': 'CEVA Logistics',
                        'type': 'Logistics Provider'}],
 'attack_vector': 'Third-Party Supply Chain Attack',
 'data_breach': {'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'Personally Identifiable Information '
                                        '(PII)',
                 'type_of_data_compromised': ['Names',
                                              'Email addresses',
                                              'Phone numbers',
                                              'Physical addresses']},
 'date_detected': '2024-07-30',
 'description': 'The Pokémon Center, the official retailer for Pokémon '
                'merchandise, confirmed a data breach stemming from a '
                'cyberattack on its logistics partner, CEVA Logistics. The '
                'incident exposed customer order details including names, '
                'email addresses, phone numbers, and physical addresses for '
                'orders shipped to the United Kingdom and Germany. Payment '
                'card information was reportedly not affected, but the breach '
                'disrupted operations, leading to delivery delays and '
                'cancellations for some customers.',
 'impact': {'data_compromised': 'Customer order details (names, email '
                                'addresses, phone numbers, physical addresses)',
            'identity_theft_risk': 'Potential risk due to exposure of '
                                   'personally identifiable information',
            'operational_impact': 'Delivery delays and cancellations',
            'payment_information_risk': 'None (payment card information not '
                                        'affected)',
            'systems_affected': 'CEVA Logistics systems (third-party logistics '
                                'partner)'},
 'lessons_learned': 'The incident underscores the growing risk of third-party '
                    'supply chain attacks, where vulnerabilities in partner '
                    'networks can expose sensitive customer data.',
 'references': [{'source': 'Pokémon Center Statement'}],
 'title': 'Pokémon Center Customer Data Exposed in Third-Party Breach via CEVA '
          'Logistics',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.