The Pokémon Company is cancelling European pre-orders for its 30th Anniversary trading cards after a cyber incident at logistics provider CEVA potentially exposed customer data. Emails shared by affected fans confirm that personal information including full names, mailing addresses, phone numbers, email addresses, and order contents may have been obtained by unauthorized parties. For collectors who secured these anniversary cards months in advance, the cancellation removes a guaranteed purchase while simultaneously putting their private data at risk.

The breach mirrors a similar incident Valve disclosed involving the same CEVA logistics firm, which impacted customers who purchased Steam Decks and Steam Machines. But a critical difference emerges in how the two companies responded: Valve proceeded with fulfilling hardware orders despite the data exposure, while The Pokémon Company has opted to fully cancel the affected Pokémon Center purchases. IGN has contacted The Pokémon Company for comment on why the remedies differ so sharply between the two cases.

What the Breach Means for Affected Customers

The Pokémon Company's notification email states that CEVA receives delivery-related information to ship Pokémon Center products, and that this data may have been compromised. The specific categories of exposed information include customer names, street addresses, postal codes, cities, countries, phone numbers, email addresses, and details of the contents of PokémonCenter.com orders. This level of personal data exposure goes beyond simple order tracking and creates tangible risks for identity theft, targeted phishing, and address harvesting for physical theft.

For European customers who pre-ordered the 30th Anniversary Cards, the cancellation means losing access to a product that was already difficult to secure. The lack of clarity compounds the frustration of a collector base already accustomed to scarcity and botched launches.

Ongoing Scarcity and Security Measures

This incident arrives against a backdrop of persistent Pokémon card scarcity that has driven retailers to extreme measures. U.S. retailer Target has begun slicing open product boxes on shelves to deter scalpers from buying entire cases. In Japan, The Pokémon Company has restricted certain releases to Japanese residents only and deployed facial recognition systems in some locations to limit daily purchase quantities for both adults and children. Despite printing a staggering 10 billion cards last year alone, demand continues to outpace supply.

The combination of high-value collectibles and logistics security failures creates a perfect storm for both scalpers and cybercriminals. When customer data tied to specific high-demand orders falls into unauthorized hands, it enables targeted theft. The CEVA breach demonstrates how a single logistics partner's security failure can cascade across multiple major brands simultaneously.

⚠️ Heads Up: European customers who pre-ordered 30th Anniversary Cards via Pokémon Center should monitor their email for official cancellation notices, check financial statements for unauthorized charges, and be wary of phishing attempts referencing their order details. The exposed data includes everything needed for convincing social engineering attacks.

Fans sharing the cancellation emails online have expressed distress over both the lost orders and the stolen personal information. The community reaction highlights a growing tension: collectors invest significant time and money securing limited products, only to face cancellation and data exposure through no fault of their own. The Pokémon Company has appeared unable or unwilling to fully keep up with demand — even with 10 billion cards printed annually — has pushed the hobby into territory where logistics security is now as critical as card authenticity.

What to Watch Next

The immediate questions center on remediation: whether The Pokémon Company will offer affected European customers priority access to future anniversary stock, what identity protection services if any will be provided, and why the company chose full cancellation where Valve chose fulfillment. The shared logistics provider suggests this may not be an isolated pair of incidents — other brands using CEVA for European distribution could face similar disclosures. Collectors should treat any order confirmation email referencing CEVA with heightened scrutiny until the full scope of the breach is understood.

Key Takeaways

  • The Pokémon Company cancelled European 30th Anniversary Card orders after a cyber incident at logistics provider CEVA
  • Customer data including names, addresses, phone numbers, emails, and order details may have been exposed
  • The same CEVA breach previously affected Valve Steam Deck and Steam Machine customers
  • Unlike Valve, The Pokémon Company is fully cancelling orders rather than fulfilling them
https://x.com/Parvytcg/status/2088360146267222273?refsrc=twsrc%5Etfw