Pokemon Center customers in the UK and Germany were warned after a CEVA cyber incident exposed delivery and order data, with some 30th anniversary card orders cancelled.

Image: gbhackers.com
Pokemon Center’s CEVA problem has become an order problem
The strongest confirmed development in the Pokemon Center data breach is not only that customer delivery information may have been exposed. It is that some affected Pokemon Center orders in the UK and Germany have been cancelled outright, including orders tied to highly anticipated Pokémon 30th anniversary products, according to Eurogamer and IGN reports based on customer emails shared online.
The breach did not originate from Pokémon Center’s own storefront, according to the customer notification reported by Eurogamer, Kotaku, IGN, TheGamer, and BleepingComputer. The incident affected CEVA Logistics, a shipping partner used to fulfil PokemonCenter.com orders for customers in the United Kingdom and Germany. CEVA is also the logistics provider linked to Valve’s recent warning to European Steam hardware customers, which is why this Pokemon cyber incident now looks like part of a broader third-party logistics exposure rather than a single-store compromise.
That distinction matters for customers trying to decide what to do next. Pokémon Center says delivery-related information was shared with CEVA so it could ship orders. The reported notification says payment and card details were not shared with CEVA, and Eurogamer reports Pokémon Center stressed that its website has not been impacted by the attack while it continues monitoring its own systems. The practical risk, based on the data named in the notification, is targeted fraud using real order details, not confirmed theft of card numbers from Pokémon Center.
Which customers and orders are affected
The confirmed affected region is Europe, specifically Pokemon Center customers in the UK and Germany, according to Eurogamer, Kotaku, IGN, TheGamer, and Yahoo’s Tech coverage. The customer email quoted by Kotaku says CEVA Logistics is the vendor Pokémon Center uses to ship products from PokemonCenter.com for customers in those two countries.
The cancellation piece is narrower than the breach itself. The sources describe affected customers receiving emails saying their recent order had been cancelled because of an “unforeseen fulfilment issue,” followed by the cyber incident warning. Eurogamer reports that Pokémon Center cancelled the orders of affected customers, while IGN notes that it remains unclear exactly how many Pokémon customers were impacted and why the orders were fully cancelled when Valve’s affected Steam hardware orders were not treated the same way.
The timing is especially painful for collectors. IGN reports The Pokémon Company is cancelling orders of Pokémon 30th Anniversary Cards following the incident, based on emails shared online by affected fans. Eurogamer says some cancelled orders include highly anticipated Pokémon 30th anniversary products. TheGamer adds that affected customers who secured Pokémon TCG: 30th Celebration pre-orders should check their email, because the set had already sold through its preorder window quickly. The key limitation is availability: Eurogamer reports customers can place a new order if their existing one was cancelled, but there is no guarantee the item will still be in stock.
What information may have been exposed
The customer data warning is specific. According to the Pokémon Center notification quoted by IGN, the information that may have been obtained from CEVA by unauthorized parties includes full name, mailing address, phone number, email address, and details of the contents of PokemonCenter.com orders. Eurogamer reports the same categories and says order information may include the contents of the order itself.
That combination is useful to scammers because it lets them sound credible. Kotaku notes that people in the breach are vulnerable to phishing scams, and TheGamer warns that attackers could pose as Valve or Pokémon Center to try to obtain additional information. A fraudulent message that already knows your name, delivery address, and the product you ordered will feel much less random than ordinary spam.
The important confirmed reassurance is also narrow. Eurogamer reports that Pokémon Center said customer payment and card details are safe because Pokémon Center does not share those details with CEVA. Yahoo’s Tech coverage says user accounts and payment details are apparently safe. Customers should treat that as good news about the known data path, not as a reason to ignore suspicious messages. The exposed data does not need to include a card number to be useful in a social-engineering attempt.
The breach window and the CEVA link
The reported timing is close but not identical across coverage. Eurogamer says the cyberattack is believed to have taken place between 29 July and 1 August. Kotaku and Yahoo quote the Pokémon Center email as saying CEVA was the victim of a cyber attack commencing on 30 July, 2026. Those accounts do not necessarily conflict, but they do show that customers should think in terms of orders handled around the end of July and early August rather than a single confirmed public timestamp.
CEVA’s role is the throughline. Eurogamer reports CEVA notified Pokémon Center after already alerting Valve about a hack affecting Steam hardware customers in Europe. Yahoo’s Tech coverage says CEVA had disclosed an incident that forced it to shut down parts of its IT infrastructure and affected eight warehouses, with other organizations also reporting knock-on effects. Yahoo also reports that around a dozen organizations were confirmed as affected and that no threat actor had claimed responsibility at the time of its report.
For Pokémon customers, the strategic reading is simple: this is a supply-chain security failure in the fulfilment layer. Pokémon Center needed CEVA to receive enough data to deliver products. Once that logistics layer was compromised, the order system’s usual separation of duties protected payment details but did not protect shipping identity, contact information, or order contents.
What to do now if you ordered from Pokemon Center UK or Germany
If you recently ordered from Pokemon Center in the UK or Germany, the first step is to check the email address associated with your order for a cancellation or cyber incident notice. The reports describe Pokémon Center notifying affected customers directly. If your order was cancelled, Eurogamer reports Pokémon Center said the credit card was not charged and that only a payment authorisation was placed, which should drop off within seven days at most. Customers should check their card or bank app for that pending authorisation rather than assuming it is a completed charge.
If you still want the product, Eurogamer reports customers may place a new order, but stock is not guaranteed. That is the hard part for anyone whose cancelled order involved 30th anniversary cards or other limited Pokémon products. A re-order may be the only path offered, but the sources do not report any automatic reservation, replacement allocation, or protected preorder queue for cancelled customers.
The security response should focus on phishing. Do not provide payment information, passwords, one-time codes, or account recovery details in response to an email, text, or phone call claiming to be about the CEVA data breach, a Pokemon customer data warning, or a cancelled anniversary card order. The reported exposed fields are exactly the kind of information an attacker can use to make a fake support message sound legitimate. The safer route is to navigate to Pokémon Center directly, sign in if needed, and use official support channels rather than links in unexpected messages.
Delays, coupons, and the questions Pokémon Center still has not answered
The disruption is also visible on the store itself. Eurogamer reports that Pokémon Center’s UK website displayed a message warning of delays in processing and shipping orders, saying some orders may take longer than usual to be dispatched and delivered. Yahoo’s Tech coverage similarly reports a site notification about delays affecting some UK orders.
Affected customers also received a goodwill offer. Eurogamer reports the email included a 20 percent off coupon valid on one order and usable until 30 November. That may soften the cost of reordering ordinary merchandise, but it does not solve scarcity if the cancelled item is gone. For card collectors, the coupon is economically secondary to allocation. A discount has little value if the product that drove the order is no longer available.
The open questions are substantial. IGN reports it is unclear how many Pokémon customers were affected. IGN also says it has not been explained why Pokémon Center purchases are being fully cancelled when Valve’s affected Steam hardware orders were not. Kotaku reports that at least one customer seeking clarity from Pokémon Center support on whether it was safe to reorder did not receive a direct answer, based on a Reddit comment. Until Pokémon Center or CEVA provides fuller public detail, customers are left with a narrow confirmed picture: the breach is tied to CEVA, the affected Pokémon Center markets are the UK and Germany, payment details are not reported exposed, some orders are cancelled, and scarce 30th anniversary card availability may not survive a forced reorder.
