LIVE · cybersecurity feed
Live wire
breach

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from third-party logistics provider CEVA Logistics. [...]

zeroday.news ·

Pokémon Center has begun notifying customers in the United Kingdom and Germany about a third-party data breach that exposed personal and order information. The incident stemmed from a cyberattack on CEVA Logistics, a vendor Pokémon Center uses to fulfill and ship orders from PokemonCenter.com in those regions.

CEVA Logistics, a subsidiary of the CMA CGM Group, confirmed it was the victim of a cyberattack that began on July 30, 2026. The breach compromised CEVA's systems between July 29 and August 1, affecting multiple retailers in Europe. This attack also impacted Valve, which previously informed its European Steam hardware customers that their names, addresses, phone numbers, email addresses, and product order details were stolen.

According to Pokémon Center's notification emails, unauthorized parties may have obtained customers' full names, mailing addresses, phone numbers, email addresses, and specific details about the contents of their PokemonCenter.com orders. The company emphasized that other customer-related information was not affected and that CEVA does not have access to customers' payment card details.

The cyberattack has led to significant disruptions, including shipping delays and the cancellation of some Pokémon Center orders. While a notice on the Pokémon Center UK website acknowledges delays, customers have reported receiving cancellation emails for various merchandise, not just highly anticipated collection products. The specific reason why the breach necessitated cancellations rather than just delays remains unclear.

CEVA Logistics operates 1,000 warehouses and handled 15 million shipments in 2025, reporting $18.3 billion in revenue. The attack disrupted eight of its European warehouses, contributing to the shipping issues. Valve's breach notification indicated that CEVA typically retains delivery-related information for up to 90 days post-order, though it is not confirmed if the same retention period applies to Pokémon Center customer data.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

LLMs and Contextual Integrity

I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic. “CIMemories: A Compositional Benchmark for Contextual Integrity of Persistent Memory in LLMs“: Abstract: Large Language Models (LLMs) increasingly use persistent memory from past interactions to enhance personalization and task performance. However, this memory introdu

phishing

Heights Finance data breach: What customers need to know

Leaked personal and financial data of around 750,000 US citizens, including SSNs and bank details, could put victims at risk of identity theft and phishing.

breach

OpenAI tightens defenses after AI agents breach research environment

Following the OpenAI-Hugging Face incident, in which an agentic collective autonomously penetrated OpenAI’s research infrastructure and another company’s production infrastructure by chaining together multiple weaknesses, OpenAI began strengthening its safety requirements. The weaknesses included previously unknown vulnerabilities and credentials leaked online. OpenAI President Greg Brockman said

CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1

security

Cyber Incident Disrupts Student Services at UT San Antonio

UT San Antonio has taken IT systems offline following a cyber incident, disrupting student registration and tuition payments days before term is due to resume

security

Microsoft tests faster Windows File Explorer, new context menu

Microsoft has started testing a faster File Explorer and a less cluttered and more customizable context menu in Windows 11 preview builds rolling out to Insiders this week. [...]