LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

Recent Breaches › Pokémon Center data breach: was my name, address and order exposed?

CRITICAL severityReportedHow we verify

Pokémon Center data breach: was my name, address and order exposed?: What Was Reportedly Exposed & What To Do

RBRecent Breaches Breach Intelligence·August 18, 2026
Pokémon Center data breach: was my name, address and order exposed?

Reported August 18, 2026.

CRITICAL
Severity
5
Data types exposed
August 18, 2026
Disclosed
ShareXLinkedInFacebookRedditWhatsAppTelegram

A data breach at Pokémon Center was disclosed on 18 August 2026, exposing full names, shipping addresses, phone numbers, email addresses, and order details of an undisclosed number of customers. If you have ordered from the store, check your email for any official notice and consider monitoring your accounts for suspicious activity.

Severity & verification
CRITICAL severityReported
Exposes financial data.
Based on public reporting. Not independently confirmed by the named organization.
Check your exposure
See every leak and listing tied to your email. We can’t confirm any single incident against the sources we search, so we won’t pretend to. 15-second check, no card, no account. Details go to your inbox.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

In a threat landscape where retail and logistics partners remain frequent targets for credential theft and supply-chain intrusion, a cyber attack on a shipping provider can quietly expose customer details far beyond the brand people recognise. Pokémon Center has told customers in the UK and Germany that an incident at its shipping partner, CEVA Logistics, beginning 30 July 2026, may have exposed personal and order information.

How many people were affected has not been published. Payment-card numbers were not held by CEVA. For anyone who ordered from Pokémon Center and wonders whether their name, address and order were among the data at risk, the disclosure is the clearest public account available so far.

Inside the incident

According to the disclosure, Pokémon Center informed UK and Germany customers that a cyber attack on CEVA Logistics, its shipping partner, began on 30 July 2026. The company indicated that the incident may have exposed customers’ full names, shipping addresses, phone numbers, email addresses and order details. Payment-card numbers were not held by CEVA, so card data is not described as part of what the shipping partner stored.

The number of people affected remains unknown in public reporting. Technical details of how the attack was carried out, how long unauthorised access lasted, and precisely which systems at CEVA were involved have not been published in the material provided. The reported date associated with this account is 18 August 2026. Beyond the customer notification summarised above, further operational findings are undisclosed.

How a breach like this happens

Incidents of this type commonly begin when an attacker gains a foothold in a logistics or fulfilment environment—through phishing, compromised remote-access credentials, unpatched software, or misuse of a legitimate supplier account. Once inside, the attacker may move laterally to systems that hold shipping manifests, customer contact fields and order references needed to label and deliver parcels.

Shipping partners routinely receive names, addresses, phone numbers, emails and product or order identifiers so that goods can be routed and customers contacted about delivery. Those records are valuable for fraud and social engineering even when payment cards are stored elsewhere. Defenders typically discover such events through monitoring alerts, unusual data access, or notification from a partner; containment then focuses on isolating affected systems, resetting access and determining what was copied. No specific threat group is attributed in the public facts for this case, and none should be assumed.

Pokémon Center data breach: was my name, address and order exposed? and its sector

Pokémon Center is the official retail channel associated with the Pokémon brand, selling merchandise, collectibles and related goods to fans, including through online orders that require fulfilment and home delivery. Organisations in this sector necessarily collect and share fulfilment data with logistics partners: who ordered, where to ship, how to reach the customer, and what is in the parcel.

A breach at the shipping layer is consequential because the customer relationship sits with the brand, while a large volume of personal and order data may sit with the carrier. Fans and collectors often place multiple orders; exposed order details can reveal purchasing habits and make follow-on scam messages more convincing. The cross-border notice to UK and Germany customers underscores that international retail supply chains concentrate similar data types in partner systems even when payment processing is separated.

The information in question

The disclosure names the following categories as potentially exposed: full names, shipping addresses, phone numbers, email addresses and order details. It states that payment-card numbers were not held by CEVA. Public reporting has not confirmed additional categories, exact file contents, or a full inventory of every field in every record.

Retail and logistics environments of this kind typically also hold internal tracking numbers, delivery instructions and account or order identifiers; whether any of those appeared in the affected CEVA systems in this incident is unconfirmed beyond the types already listed. Readers should treat only the named categories as the disclosed scope and regard anything else as unknown until further official detail appears.

Why it matters

For affected individuals, names combined with shipping addresses, phone numbers and emails enable targeted phishing, smishing and courier-impersonation scams that reference a real order. Order details can make those messages more plausible and may reveal interests or household information useful for broader social engineering. Address data can also increase nuisance contact or physical-mail fraud risk, though the disclosure does not describe financial account takeover via cards held at CEVA.

For the organisation and its partner, the incident creates notification duties, customer-support load and reputational pressure across markets that received the warning. Because the headcount of affected people is unpublished, the full scale of residual risk—and how long monitoring may be needed—remains harder for the public to judge. Separation of payment-card storage limits one major harm path, but identity and logistics data still carry lasting misuse potential.

If your data was in this breach

If you ordered from Pokémon Center and may fall within the UK or Germany customer groups notified, treat the named data types as potentially exposed and take measured steps:

Public detail on total numbers affected remains limited, so individual confirmation may not arrive quickly. Readers can run a free exposure scan of their email to check whether their information has surfaced in known breach data, and should rely on official Pokémon Center or CEVA updates for any expansion of the disclosed scope.

AICompiled with AI assistance from public sources and published under our editorial standards.

Editorial & sourcing policy
Recent Breaches is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data, and we do not hold the data claimed in leak-site listings. Incidents are compiled from publicly accessible sources and threat-intelligence platforms and are reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — write to support@galaxywarden.com or press@recentbreaches.com.
Check if you’re exposed →

How this breach connects

Method

More recent breaches

Simian Drukland data breach: what we know and what customers should doAugust 17, 2026TD Bank data breach: Vermont AG confirms notice involving SSNs and accountsAugust 15, 2026Did SafePal leak my home address? What the 2026 breach actually meansAugust 18, 2026ssf-int.com ssf-ing.de Listed by Incransom Ransomware GroupAugust 18, 2026

Latest breaches

Read GalaxyWarden’s full analysis of the Pokémon Center data breach: was my name, address and order exposed? →

Based on public reporting

Breach listings — particularly those originating from ransomware or leak sites — are third-party claims that may be unverified, incomplete, or inaccurate. A listing does not by itself confirm that a breach occurred or that any specific data was exposed. Severity is an automated assessment, not a definitive rating. Verification status is shown where available.

Attributions to threat groups and methods reflect public reporting and, in some cases, unverified claims made by the groups themselves; they may be incomplete or later revised. Recent Breaches and GalaxyWarden are independent and are not affiliated with, and do not endorse, any company or group named on this page. This information is aggregated from public sources for awareness only and is not legal, security, or investment advice.

ShareXLinkedInFacebookRedditWhatsAppTelegram