A CEVA Logistics cyberattack between July 29 and August 1, 2026 disrupted eight European warehouses and may have exposed Pokémon Center customers’ names, addresses, contact details, and order information. Some Pokémon Center orders in the United Kingdom and Germany—including reported 30th anniversary card orders—wer...
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened in the cyberattack on CEVA Logistics, a CMA CGM subsidiary and Pokémon Center’s logistics partner, that began between July 29. Article summary: CEVA Logistics suffered a supply-chain cyberattack that disrupted European fulfillment and may have exposed delivery and order data held for its retail clients. Pokémon Center says the incident affected UK and German cus. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, click
A cyberattack on CEVA Logistics, the fulfillment provider used by Pokémon Center in the United Kingdom and Germany, disrupted European warehouse operations and may have exposed customer delivery and order data. The incident did not originate in Pokémon Center’s website or customer-account systems, and available reports say payment-card information was not exposed through the Pokémon Center impact.
The immediate customer problem is twofold: some orders were canceled or delayed, and affected shoppers may now receive unusually convincing scams referencing real products, addresses, or order problems.
CEVA Logistics is the France-headquartered contract-logistics arm of CMA CGM. It operates more than 1,000 warehouses worldwide and handles fulfillment and shipping for multiple retailers and technology companies.
Attackers accessed CEVA systems from approximately July 29 through August 1, 2026. The intrusion disrupted parts of CEVA’s European contract-logistics operations; reporting identified eight affected warehouses, where shipments were halted or could not be dispatched. CEVA notified affected customers on August 1 that goods held at the disrupted facilities were not shipping.
CEVA was still investigating in the latest reports. The intrusion method, the complete number of affected people, the precise data accessed, and whether information was removed have not been publicly established. No ransomware group or other attacker had claimed responsibility in the available reporting.
Pokémon Center notified customers in the UK and Germany that CEVA had suffered a cyberattack affecting information used to fulfill PokémonCenter.com orders. The information was held by the logistics provider so it could deliver products; Pokémon Center said the incident was not a compromise of its own customer accounts or payment processing.
Customers reported two main operational effects:
The Ghost Chateau Cyndaquil keyring has been discussed in customer reports in connection with the disruption, but the available evidence does not show that Pokémon Center publicly identified that specific SKU as compromised or officially canceled. It should therefore not be presented as a confirmed example.
Pokémon Center has not publicly explained the decision for individual orders. Possible operational explanations include unreliable fulfillment records, difficulty locating or allocating inventory, or a need to rebuild affected orders safely. Those are reasonable possibilities—not confirmed findings.
A cancellation also does not prove that the associated customer data was stolen, nor does it prove that the data was safe. The order status may reflect a fulfillment decision made after the incident rather than the outcome of the forensic investigation.
For affected Pokémon Center customers, reported or potentially exposed information includes:
This is not the same as a password or payment-card breach. Pokémon Center’s notifications and reporting indicate that its own website and customer-account systems were not compromised and that payment-card information was not accessed through this incident.
That distinction lowers the direct risk of card theft or account takeover from the CEVA exposure. It does not eliminate risk: a scammer with a real name, address, email address, and product detail can make a fake delivery or refund message look authentic.
CEVA’s role as a shared logistics provider meant that the incident reached beyond Pokémon Center. Organizations reported as affected or notifying customers included:
Reporting described roughly a dozen affected organizations, but the list may not be complete while the investigation continues.
Valve separately warned European customers who had purchased physical Steam hardware, including the Steam Deck, Steam Machine, or Steam Controller. The potentially exposed information included delivery-related details, while Valve said Steam passwords, payment-card numbers, and Steam Guard codes were not involved.
This was therefore a supply-chain compromise at a logistics provider rather than a direct breach of Steam or Pokémon Center.
The exposed information is particularly useful for social engineering because it can help an attacker create a message that appears to confirm something the recipient already expects. Treat unsolicited messages as suspicious even when they mention a genuine product, order, address, or cancellation.
Common lures could include:
CEVA has separately warned that scammers use its name, logo, letterhead, employee identities, and fake websites in fraudulent correspondence.
The central lesson is that a logistics breach can affect customers even when the retailer’s main website remains secure. In this case, the known exposure is centered on delivery and order information, while the reason for individual Pokémon Center cancellations and the full extent of the CEVA compromise remain unresolved.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
A CEVA Logistics cyberattack between July 29 and August 1, 2026 disrupted eight European warehouses and may have exposed Pokémon Center customers’ names, addresses, contact details, and order information.
A CEVA Logistics cyberattack between July 29 and August 1, 2026 disrupted eight European warehouses and may have exposed Pokémon Center customers’ names, addresses, contact details, and order information. Some Pokémon Center orders in the United Kingdom and Germany—including reported 30th anniversary card orders—were canceled, while others were delayed.
Valve, bol, De Bijenkorf, ING, Ace & Tate, and Ajax were among other organizations linked to the incident; the full scope remains under investigation and no attacker has publicly claimed responsibility.