OptMsg Breach Breakdown - Pokémon Center data breach

Pokémon Center Data Breach — What Happened and What To Do

The email arrives on a Monday and it is an apology. The order you placed — the one for a birthday still three weeks away — has been cancelled “due to an unforeseen fulfilment issue.” You reply asking why. Nothing comes back.

Then a second email arrives. This one knows the order number. It knows what was in the box. It knows the address the box was going to, because it prints it back to you at the top. It says there is a small redelivery fee to release the parcel, and here is the link.

Nothing about that second message looks wrong, because every detail in it is right.

What Company Was Breached?

The breach did not happen at Pokémon Center — it happened at CEVA Logistics, the third-party company Pokémon Center uses to ship PokemonCenter.com orders to customers in the United Kingdom and Germany.

That is the part worth sitting with. The people affected have no relationship with CEVA Logistics. They ordered a plush toy or a card set from a website they trust, and their details were passed on to a shipping contractor so the parcel could arrive.

CEVA is not a small operator. It is a subsidiary of the CMA CGM Group, the world’s third-largest shipping company; BleepingComputer reports that it runs about 1,000 warehouses, handled 15 million shipments last year, and reported $18.3 billion in revenue in 2025. The same incident disrupted eight of its European warehouses, and Pokémon Center is one of several retailers caught by it — Valve notified European Steam hardware customers of the same CEVA attack on 10 August, and Dutch retailers were told on 1 August.

When Did the Breach Occur?

Pokémon Center’s notification to customers says the attack on CEVA Logistics commenced on 30 July 2026; Valve, notifying its own customers about the same incident, said attackers had access to CEVA’s servers between 29 July and 1 August 2026.

The two dates differ by a day. Both are reproduced here as each company stated them, rather than reconciled into one number that neither company published.

  • 29–30 July 2026 — the intrusion at CEVA Logistics begins, per the two notifications.
  • 1 August 2026 — CEVA informs European retailers that a cyberattack has disrupted operations at eight of its warehouses.
  • 7 August 2026 — Valve learns that Steam customer information was likely compromised.
  • 10 August 2026 — Valve emails affected European customers.
  • 17 August 2026 — Pokémon Center customers in the UK and Germany receive cancellation and notification emails; BleepingComputer reports it the same day.

Between the intrusion and the Pokémon Center notification, roughly two and a half weeks passed.

What Was Stolen?

Pokémon Center says unauthorised parties may have obtained customers’ full names, mailing addresses, phone numbers, email addresses, and details about the contents of their PokemonCenter.com orders.

No figure has been published for how many people are affected, and this Breakdown is not going to invent one. A Breach Breakdown usually leads on a record count. Here there isn’t one: Pokémon Center’s notification does not give a number, the company has not responded to press enquiries, and the incident has not been catalogued by Have I Been Pwned. What is known is the scope — customers of PokemonCenter.com in the United Kingdom and Germany — and the fields.

What appears not to be in the set, according to the same notification: Pokémon Center says CEVA does not have access to customers’ payment card details, and that other information related to customers and their orders was not impacted.

Valve’s notification about the same incident describes the same shape of data — names, addresses, phone numbers, email addresses, and the type and price of products ordered — and says CEVA had no access to payment information, passwords or Steam Guard codes.

One detail from Valve’s notice has no confirmed equivalent on the Pokémon Center side: Valve said CEVA retains delivery-related information for up to 90 days after an order, which is how it worked out who to warn. Whether the same retention window applies to Pokémon Center orders has not been stated.

How Can This Breach Be Used Against You?

A name, a home address, a phone number, an email address and a description of what someone actually ordered is the combination that makes a scam message sound like it came from a company you really do business with.

Valve put this to its own customers more directly than most breach notices manage, warning that they may be targeted by email, SMS or voice phishing impersonating Steam, Valve or delivery companies — and that the sender “may quote your address back to you to prove they’re genuine.”

Three concrete things that follow from a file shaped like this:

  • A redelivery or customs-fee message. It refers to a real parcel, to the right address, and asks for a small payment to release it. The amount is deliberately trivial; what the scammer wants is the card details, not the fee.
  • A refund email for the cancelled order. This one is unusually dangerous here, because the cancellations were real. Somebody who has just been told by Pokémon Center that their order was cancelled has already been trained to expect a follow-up message about it.
  • A text to your actual mobile number about a delivery. A phone number in a breach file is a second door into the same person, and it is the one most people have no filter on at all.

The through-line is that each of these arrives in a channel you did not open. Somebody now holds the details needed to start a conversation with you whenever they choose to.

How to Protect Yourself

Most of what is worth doing here has nothing to do with any product, including ours. Do these first.

  1. Treat every message about this order as unverified — including the ones that are probably genuine. Do not use links in the email. Go to pokemoncenter.com yourself, sign in, and look at the order there.
  2. Do not pay a fee to release a parcel from a link. A small redelivery or customs charge requested by email or text is the most common form this scam takes. If you think a charge might be real, look up the courier’s number independently and ask them.
  3. Expect the refund conversation to be started by someone else. If a message offers to process a refund for the cancelled order and asks for card details to do it, that is not how a retailer refunds an order it cancelled itself.
  4. Check your address at haveibeenpwned.com — it is free and needs no account. One caveat specific to this incident: the CEVA dataset has not been catalogued there, so a clean result does not rule you out of this one.
  5. A credit freeze is not the response this breach calls for. Payment card numbers, passwords and identity documents are not among the fields described. Advice to freeze your credit is good advice about a different kind of breach, and following it here would cost you an afternoon and change nothing.
  6. If you are in the UK or Germany, you can report a scam message that follows. Valve said it was notifying the data protection authorities in the affected countries; if a phishing attempt reaches you, reporting it locally is what turns one person’s experience into a pattern someone can act on.

How OptMsg Helps

OptMsg uses patent-pending opt-in technology: mail from a sender you have not approved is delivered to Trash rather than to your inbox, and the app auto-deletes the contents of Trash after 30 days.

Be clear about what that does and does not mean. OptMsg would not have stopped the attack on CEVA Logistics. That happened inside a shipping contractor’s systems, which is not something an email product touches, and any company claiming otherwise is selling you something. What an opt-in inbox changes is what a leaked email address is worth to the person holding it afterwards.

An email address in a breach file is not embarrassing on its own. It is a channel. It is the reason the fake redelivery notice can reach you at all. On an ordinary inbox, anyone who has the address can start a conversation, and your protection is that you personally notice something is off in the four seconds you spend looking at it. On an opt-in inbox, mail from a sender you have not approved does not arrive in front of you in the first place.

The honest objection to that design is: what if something important lands in Trash and I miss it? OptMsg’s answer is Community Recommendations. When a message from an unapproved sender lands in Trash, OptMsg checks whether many other OptMsg users have opted in to that sender as trusted; if they have, the message is flagged and you get a push alert telling you there is something in Trash worth a look. That runs on other people’s choices, not on a filter guessing, and it sits inside the 30-day window before Trash is emptied.

If this breach is the moment you would rather decide who is allowed to email you than keep sorting out who already has, that is what OptMsg’s security-first inbox is built around. You can set one up here.

Create Your Account

Sources

A note on sourcing. Pokémon Center has not published a public statement page about this incident. The notification is a customer email, reported and quoted by BleepingComputer, and the company had not responded to press enquiries at the time of writing.

Frequently Asked Questions

Was Pokémon Center itself hacked?

No. The breach happened at CEVA Logistics, the third-party company Pokémon Center uses to ship PokemonCenter.com orders to customers in the United Kingdom and Germany.

What information was exposed in the Pokémon Center data breach?

Pokémon Center says unauthorised parties may have obtained customers’ full names, mailing addresses, phone numbers, email addresses, and details about the contents of their orders. The company says CEVA does not have access to customers’ payment card details.

How many Pokémon Center customers were affected?

No figure has been published. Pokémon Center’s notification describes the affected group as customers in the United Kingdom and Germany without giving a number, and the incident has not been catalogued by Have I Been Pwned.

Why was my Pokémon Center order cancelled?

Pokémon Center’s notification email attributes the cancellations to “an unforeseen fulfilment issue” and then describes the cyberattack on its logistics provider. The company has not explained why the attack required cancellations rather than delays.

Scroll to Top