Back to Blog
medium severity August 18, 2026 · 4 min read Unverified claim — what this is

Pokémon Center data breach: what UK and Germany customers need to know

If you have an account with Pokémon Center, here’s what is being claimed, and what it would mean for you.

Pokémon Center has emailed some customers that CEVA Logistics, which ships its UK and Germany orders, was hit by a cyber attack starting 30 July 2026. Names, mailing addresses, phone numbers, emails, and order details may have been taken; payment cards were not. Pokémon Center has not said how many people were affected.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Pokémon Center data breach: what UK and Germany customers need to know

Pokémon Center has emailed some customers that CEVA Logistics — the company that ships PokemonCenter.com orders to the United Kingdom and Germany — was the victim of a cyber attack beginning on 30 July 2026. In those emails, Pokémon Center said unauthorized parties may have obtained customers’ full names, mailing addresses, phone numbers, email addresses, and details about the contents of their orders. Payment-card details were not accessed.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
The free scan shows you every leak tied to your email, and which look-up sites are publishing your name, address and family alongside it. We write to 582 companies.
Check if you are in this breach — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Some recent orders were cancelled because of what the emails called an “unforeseen fulfilment issue” tied to the incident. The public UK site and support pages mention only processing and shipping delays. Pokémon Center has not said how many people or orders were affected, and it has not published a statement beyond those private emails.

Your card being safe is not the same as you being untouched

The first line you will see about this is the reassuring one: a shipping contractor was attacked, not the shop’s checkout, and card numbers were not taken. That is true. It is also the least useful part of the news if you are trying to decide what this means for you.

What left CEVA is a working contact sheet. A name, a home address, a phone number, an email, and a note of what that person had just ordered from the official Pokémon store. That is enough for someone to write to you about an order you really placed, to mention a cancellation you may already have seen, or to arrive in your inbox as “CEVA” or “Pokémon Center support” with details that feel internal.

It is also enough to know that a parcel was meant for that address. Coverage that leads with “no payment cards” is answering a question most people are not actually asking. The question is whether a stranger can now talk to you, about your order, at your house. For customers whose records were in CEVA’s files, the honest answer is yes.

That does not mean every Pokémon Center customer is in the file. CEVA was used for UK and Germany shipments. If you have never had a PokemonCenter.com order sent to those countries, this incident as described is not about your data. If you have, Pokémon Center has not said whether every recent order was included or only some, or which dates sit in the stolen set. There is no public list, and no checker can honestly tell you that you were — or were not — in this specific incident.

What you should actually expect

  • Emails, texts, or calls about a cancelled Pokémon Center order, a reshipment, a refund, or a delivery problem. Some orders really were cancelled, and the company already used that wording, so the first scams will copy it.
  • Contact that uses your real name and address and claims to be Pokémon Center, CEVA, or a courier. Correct details do not make the sender genuine.
  • The official website will keep talking about delays and will not spell out a breach. That is already how the public pages read. Silence there is not a sign you were spared.
  • Unexpected card charges are not the fingerprint of this incident. If a card you used is charged strangely, treat that as a separate problem with your bank.

What you cannot undo — and what still helps

If your details were in CEVA’s files, they are out. A name, a mailing address, a phone number, an email address, and a description of an order cannot be pulled back. No company can delete them from whoever took them. Anyone offering to remove you from the breach is selling something they cannot do.

What still helps, in this order:

  • Treat unsolicited contact about a Pokémon Center or CEVA order as a scam, even if it cites a real cancellation or a real product. Use only an account page or phone number you already had — not a link or number in the message.
  • Watch the inbox and the phone number you used at checkout. That is how follow-up scams will arrive. You do not need to replace a card because of this incident alone.
  • Ignore unexpected requests to confirm an address or pay a small fee to release a parcel. Those messages will fit this leak exactly.
  • Cut back the extra data that sits next to your name and address on people-search sites. A leaked shipping record becomes much more dangerous when it can be joined to listings that add relatives, extra phone numbers, employers, and previous addresses. Those listings, unlike the stolen CEVA file, can actually be taken down through each site’s opt-out process. That is the lever you still have.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Pokémon Center is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium
Disclosed August 18, 2026
Affected Unconfirmed
Data exposed Full namesMailing addressesPhone numbersEmail addressesOrder contents
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email