# When the Delivery Driver Leaks Your Data: Pokémon Center and the CEVA Logistics Breach


The Pokémon Company's merchandise arm is not a hospital, a bank, or a defense contractor. It sells plushies and trading cards. Which is exactly why this breach matters — not for who got hit, but for *how*, and for what it tells us about an attack surface most organizations have spent the last decade pretending doesn't exist.


Pokémon Center has begun notifying customers in the United Kingdom and Germany that a third party compromised their personal and order data. The third party in question: CEVA Logistics, a global freight and supply chain company that handles fulfillment on behalf of the brand. The breach was serious enough that Pokémon Center cancelled some customer orders outright — not a typical PR move for a company trying to minimize damage.


---


## The Vendor Is the Vulnerability


CEVA Logistics isn't a mom-and-pop shipping shop. It's a major multinational logistics operator with operations spanning more than 160 countries. It handles fulfillment for consumer brands, industrial shippers, and retail operations worldwide. Which means one successful intrusion into CEVA's systems isn't a single-brand problem — it's a master key to the data of potentially dozens of companies and hundreds of thousands of end customers.


This is the third-party logistics breach playbook: attackers don't need to crack the brand's perimeter. The brand has a security team, a CISO, an incident response retainer. The logistics vendor has an ERP system and a prayer.


Customer data flowing through a logistics relationship typically includes names, shipping addresses, order contents, and sometimes payment metadata — exactly the type of high-value PII that feeds credential stuffing campaigns, targeted phishing, and the kind of physical-world social engineering that rarely makes headlines but causes disproportionate harm. Someone who knows your order history and delivery address has more leverage than someone holding only your email.


The cancellation of some orders — an unusual detail — suggests either that access persisted long enough for active manipulation of the order management system, or that Pokémon Center made a risk decision to pull orders rather than ship to addresses they couldn't trust hadn't been tampered with. Either reading is worse than a simple data grab.


---


## A Pattern Nobody's Fixing


CEVA joins a long list of logistics providers that have become breach vectors. In 2021, CEVA itself was hit by ransomware — the REvil group claimed responsibility and threatened to publish data. In 2022, it was Expeditors International that took systems offline after a cyberattack. Last year, breaches involving fulfillment and freight platforms showed up repeatedly in retail sector incident reports.


The reason this pattern keeps repeating is structural. Retailers and brands outsource fulfillment to reduce capital expenditure and operational overhead. That same outsourcing decision also outsources significant data risk — but without the contractual teeth, audit rights, or security standards that would normally accompany that transfer. Security teams at brands often have limited visibility into their logistics partners' control environments. They receive assurances, not evidence.


The EU's new NIS2 directive, which came into force at the end of 2024, explicitly targets supply chain security and obliges companies to assess the cybersecurity practices of their direct suppliers. This breach, affecting UK and German customers specifically, lands squarely in that regulatory frame. Whether CEVA was adequately evaluated by Pokémon Center's vendor security program is a question regulators in both jurisdictions may now be positioned to ask.


---


## What Affected Customers Should Watch For


For UK and German Pokémon Center customers who received a breach notification, the immediate risk profile is moderate but real:


Phishing and smishing using order details to impersonate Pokémon Center or delivery carriers. These attacks are effective precisely because the attacker knows what you ordered and can reference it to establish false legitimacy.


Address-based targeting, particularly for high-value orders. Collectibles and limited-edition merchandise attract resellers and opportunistic theft; knowing someone recently ordered a sealed booster box tells a bad actor something actionable.


Credential reuse attacks if customers used the same password on Pokémon Center that they use elsewhere. Standard advice, chronically ignored.


Customers should treat any incoming communication referencing their order — email, SMS, or phone — as suspect until verified through official channels. No legitimate follow-up from Pokémon Center should require login credentials or payment information.


---


## HackWire Analysis


The Pokémon Center breach is not a story about inadequate perimeter security at a beloved consumer brand. It's a story about how the logistics industry has become one of the most underdefended and overexposed sectors in the supply chain attack surface — and how consumer companies continue to transfer data to these vendors with insufficient contractual and technical safeguards.


CEVA Logistics was hit by ransomware in 2021. A company with that incident history operating as a trusted data processor for consumer brands in 2025 should have come with hard questions attached: What did the post-incident remediation actually accomplish? What certifications does CEVA hold and when were they last audited? What data minimization controls exist to ensure CEVA only retains what it genuinely needs for fulfillment?


Most vendor security questionnaires don't ask those follow-up questions. They ask about SOC 2 reports and then file the response.


What makes this breach particularly instructive for defenders is the combination of two factors: a repeat-target logistics vendor and a consumer-facing brand with no obvious security-forward positioning. Brands like Pokémon Center attract customers who are trusting by default. They are not thinking about their data when they order a limited-edition Charizard plush. That trust asymmetry is exactly what makes these companies attractive to attackers — not the brand itself, but the volume of trusting customers whose data flows through comparatively soft third-party systems.


For any company using third-party logistics: your data sharing agreement with your fulfillment partner is a security document. Treat it like one. Conduct tabletop exercises that include your logistics provider. Require contractual notification timelines. And audit, actually audit — don't accept self-reported compliance as adequate.


The trend line here is not improving. Expect more of these.


— *HackWire Editorial*


---


## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)