Pokémon Center cancels European orders after CEVA Logistics cyberattack

The Pokémon Company has canceled a batch of pending Pokémon Center orders in the United Kingdom and Germany after a cyberattack hit CEVA Logistics, the third-party vendor it relies on to ship products in those markets. Affected customers received emails confirming the cancellations, including some pre-orders for the upcoming Pokémon TCG 30th Celebration expansion, one of the year's most sought-after sets, which had already sold out shortly after its pre-order window opened.
CEVA breach exposes customer data
Pokémon Center's breach notifications state that CEVA Logistics was hit by a cyberattack beginning around July 30, 2026, with some reports placing the intrusion as early as July 29. The attack compromised systems CEVA uses to process delivery information for retail clients, exposing data tied to PokemonCenter.com orders. The information had included the likes of customers' full names, mailing addresses, phone numbers, email addresses, and order details. The company says payment card details and account credentials were not affected, as that information is handled separately from CEVA's systems.
The incident is part of a larger breach at CEVA Logistics, which disrupted operations across roughly eight of its European warehouses. Other CEVA clients, including Valve's European Steam hardware operations, have reported similar customer data exposure from the same attack, suggesting the fallout extends well beyond the Pokémon brand and into the wider logistics supply chain.
Cancellations followed vague initial messaging
Before disclosing the cyberattack, Pokémon Center initially told customers their orders were canceled due to an "unforeseen fulfilment issue," without mentioning the breach. The company's UK storefront currently displays a separate notice warning of processing delays for some orders, though many affected customers report outright cancellations rather than delays. It remains unclear why the incident required cancellations instead of simple shipping delays, and Pokémon Center has not disclosed how many orders or customers were affected in total.
Pokémon Center has not issued a formal public statement beyond the customer notification emails, and details have largely surfaced through screenshots shared by affected shoppers and reporting from security outlets that reviewed the messages.
As with similar third-party breaches, affected shoppers should be cautious of unsolicited emails referencing their order numbers, since exposed contact and order data of this kind is often reused in follow-up phishing attempts that impersonate legitimate retailers.










