Back to Blog
medium severity August 19, 2026 · 3 min read Unverified claim — what this is

Pokémon Center data breach: what UK and Germany customers should know

If you have an account with Pokémon Center, here’s what is being claimed, and what it would mean for you.

A cyberattack on CEVA Logistics, the firm that ships Pokémon Center orders to the UK and Germany, may have exposed customer names, home addresses, phone numbers, emails and order details. Pokémon Center’s own systems and payment cards were not involved. Some recent orders were cancelled or delayed.

— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Pokémon Center data breach: what UK and Germany customers should know

In late July 2026 a cyberattack hit CEVA Logistics, the company Pokémon Center uses to ship orders from PokemonCenter.com to customers in the United Kingdom and Germany. CEVA told Pokémon Center the attack began on 30 July; CEVA separately said it most likely started on 29 July and that it notified its clients on 1 August. Eight of CEVA’s European warehouses were disrupted. Pokémon Center’s own systems were not broken into.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
The free scan shows you every leak tied to your email, and which look-up sites are publishing your name, address and family alongside it. We write to 582 companies.
Check if you are in this breach — free scan →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Pokémon Center then emailed affected customers that unauthorized parties may have obtained full names, mailing addresses, phone numbers, email addresses, and details of what was in the order. Payment-card details and account information were not included, because CEVA never held them. Some recent orders were cancelled, which the company described as an unforeseen fulfilment issue. Its UK support pages showed a banner about delays. No number has been published for how many customers or orders were involved.

Your card was never in this file. Your home address may have been.

Most coverage of this incident has led with the reassuring half: a contractor was hit, not Pokémon Center; cards and passwords were untouched; the company’s own shop was not breached. All of that is true. It is also not the part that changes anything for you at home.

A shipping company holds the packing information. That is your name, the door the parcel was meant to reach, a phone number, an email address, and a description of what you bought. That is the set Pokémon Center says may now have been obtained. It is not a bank breach. It is a list of real households, at real addresses, tied to specific Pokémon Center orders, with a way to call or email each person.

That combination is what a later scam needs in order to sound genuine. Someone can write to you about a cancelled order, name the items, and ask you to “reconfirm” a delivery slot or pay a small reshipping charge. They will not be guessing. The public notice on Pokémon Center’s UK support site mentioned only delays. It did not mention the data. Easy to miss if you never opened the email.

What to actually expect

  • Messages — email, text or phone — about a delayed or cancelled Pokémon Center order that use your real name and what you bought. The official company email already went out; a second message asking you to click, log in, or pay a fee is not part of that.
  • If you had a recent order heading to the UK or Germany, it may already have been cancelled or held. That is a warehouse problem, not a request for you to send money or card details to get it moving.
  • You should not expect surprise charges on the card you used. CEVA did not have payment-card details, and Pokémon Center says those were not affected.
  • There is no public list of whose records were involved, and no reliable way to look yourself up. An email from Pokémon Center is the notice they say they sent to affected customers. Silence is not a guarantee either way.

What you can and cannot fix

If your name, mailing address, phone number, email address and order details were in the CEVA records for a UK or Germany shipment, that copy cannot be recalled. Nobody can delete it from whoever took it. An address that is out, is out.

  • Treat any unexpected contact about this order as a scam, even when the details are right. Do not click a link, read out a code, or pay a fee to “release” a parcel. If you need to check an order, type the Pokémon Center site address yourself or use the app you already have.
  • Tell the other people in your household. A call or text that uses your name and a real order can sound official to whoever picks up the phone.
  • Shrink the extra information sitting next to your name and address online. A leaked shipping record becomes much more useful when it can be joined to people-search pages that add relatives, extra phone numbers, employers and previous addresses. Those listings, unlike the stolen copy, can actually be taken down. Search your name and home address, and use each site’s own removal process for the results that map your household.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove — and removing them is what we do.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Pokémon Center is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity Medium
Disclosed August 19, 2026
Affected Unconfirmed
Data exposed Full namesMailing addressesPhone numbersEmail addressesOrder details
Unverified claim — what this report is
This page documents a public listing on a ransomware/extortion group’s leak site, tracked via public threat-intelligence sources. A listing is the attacker’s claim. GalaxyWarden aggregates and reports such claims; we have not independently verified that a breach occurred, what data (if any) was taken, or the accuracy of anything the group asserts, and the named organisation has not necessarily confirmed the incident. Sections above describe what the listing shows and the group’s documented history — not verified findings about the named organisation. If you represent this organisation and believe anything here is inaccurate, tell us and we’ll review it promptly.
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email