
Pokemon Center’s Data Breach Reveals the Hidden Risk in Every Third-Party Vendor Relationship

Pokemon Center emailed customers in the United Kingdom and Germany this week confirming that their personal data had been stolen — not through a breach of Pokemon Center’s own systems, but through a cyberattack on CEVA Logistics, the third-party vendor the company uses to ship orders in both markets. The exposed information included names, postal addresses, phone numbers, email addresses, and order details. The mechanism was a supply chain attack. The damage was real.
A Betting-Market Observer on Vendor Risk Across Transaction-Heavy Platforms
The LTBet Team, which covers the Lithuanian sports betting market through bookmaker analysis, betting guides, and community-driven industry reporting, noted that the breach makes visible a structural pressure that reaches well beyond retail e-commerce.
The breach mechanism is the instructive part. CEVA Logistics — not Pokemon Center’s own checkout systems — was the entry point, per Forbes. Muhammad Yahya Patel, vCISO and cybersecurity advisor at Huntress, stated plainly that third-party risk programs must extend to logistics, fulfillment, and operational partners with the same scrutiny applied to technology vendors. That principle applies wherever customer transactions flow through vendor-managed layers.
“Any online platform handling high volumes of customer transactions is only as secure as the third-party vendors woven into its checkout and fulfillment chain. The Pokemon Center breach makes that structural dependency impossible to ignore.”
The team pointed to Lithuania’s online betting market as a direct parallel. LT BET, operating in that market, faces exactly the same imperative the breach exposes: continuous vetting of payment gateways and active monitoring of third-party checkout integrations, because a failure at the vendor layer becomes the operator’s problem in the eyes of every customer who trusted it with their data.
CEVA Logistics Attack: What Happened and What Data Was Taken
CEVA Logistics informed Pokemon Center that it was the target of a cyberattack commencing on July 30, 2026. Reporting places the attack window between July 29 and August 1. The breach notification Pokemon Center sent to affected customers in the UK and Germany stated the situation directly.
“CEVA Logistics (‘CEVA’), the vendor Pokemon Center utilizes to ship product from PokemonCenter.com for customers in the United Kingdom and Germany, has informed us that unfortunately they were a victim of a cyber attack commencing on 30 July, 2026.”
The data exposed covered a substantial range of personally identifiable information: full names, home addresses, phone numbers, email addresses, and order records. One meaningful carve-out exists. CEVA Logistics did not have access to customer payment card details, and no payment card data was taken in the breach. That is a genuine distinction for affected customers, though it does little to reduce the other downstream risks the stolen data creates.
Steam Users Also Caught in the Same Breach
Pokemon Center is not the only company whose customers were caught in the CEVA Logistics incident. Valve notified Steam users that their customer data was also stolen in the same attack, making this a multi-brand breach rather than a Pokemon Center-specific event.
The operational damage is already visible. At the time of reporting, Pokemon Center’s UK website was displaying a prominent banner stating the site is “currently experiencing delays in processing and shipping orders.” No mention of the data breach appeared on the site itself. Bleeping Computer first reported the CEVA Logistics breach on August 17, one day before the Forbes report was published.
Cybersecurity Experts Flag Phishing Risk and Vendor-Program Gaps
The cybersecurity community’s reaction to the breach centered on two points: the structural inadequacy of most third-party risk programs, and the concrete downstream threat the stolen data poses to affected individuals.
Patel identified the core problem. Customers extended their trust to Pokemon Center, not to its logistics contractor.
“That distinction matters, and most consumers don’t know it exists until a breach notification lands in their inbox.”
His prescription was direct: third-party risk programs need to reach logistics, fulfillment, and operational partners with the same rigor applied to technology vendors. Most do not, and this breach is a visible consequence of that gap.
Donnan Mallon, threat intelligence analyst at Talion Cyber Security, focused on what attackers can now do with the data in hand.
“The information compromised is very significant, and it could be used in multiple ways to execute attacks. Not only do attackers have full contact details for individuals, they also have information on orders, which could all be used to craft tailored phishing scams.”
The combination of contact details and order history is particularly useful for constructing convincing fraud. A message referencing a real order, addressed to a correct name at a correct address, is far harder for a recipient to identify as malicious than a generic phishing attempt. UK and Germany Pokemon Center customers should treat any incoming message referencing their orders or account details with heightened caution in the weeks ahead — Mallon’s assessment leaves little ambiguity about the scale of the threat.