Coupang, South Korea's largest e-commerce platform, confirmed a major data breach that exposed the personal information of approximately 33.7 million customers, representing a significant portion of the country's population. The breach, which was initially detected on November 18 with only 4,500 accounts affected, was later found to be far more extensive, involving names, email addresses, phone numbers, shipping addresses, and partial order histories. Coupang stated that payment card details and login credentials were not compromised. The unauthorized access reportedly began on June 24, originating from overseas servers, and was facilitated by weaknesses in Coupang's authentication key management, including the failure to rotate or revoke signing keys after responsible employees left the company.
South Korean authorities, including the National Police Agency, Korea Internet & Security Agency, and the Personal Information Protection Commission, have launched investigations into the incident, focusing on Coupang's compliance with data protection obligations. The government convened an emergency meeting and announced plans for stricter oversight and potential sanctions if safety measure violations are confirmed. Coupang has since blocked the unauthorized access route, enhanced internal monitoring, and engaged external security experts. The company issued public apologies and is cooperating with authorities to prevent further harm, while also notifying affected customers and providing support channels for inquiries.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said the breach may have been enabled by failures to rotate or revoke authentication signing keys after an employee's departure. The allegations sharpened scrutiny of Coupang's offboarding, access control, and key management practices.
In the aftermath of the public disclosure, affected users filed lawsuits and officials discussed stronger sanctions. Reports said Coupang could face major regulatory penalties, potentially including a record fine if violations of data protection rules are confirmed.
On 2025-12-01, Coupang publicly confirmed a massive data breach affecting about 33.7 million customer accounts, roughly 65% of South Korea's population. Exposed data included names, email addresses, phone numbers, shipping addresses, and partial order history, while passwords and payment card data were reportedly not compromised.
Initial investigations identified a former Chinese Coupang employee, reportedly tied to authentication systems, as the main suspect. Multiple reports said the case appeared to be an insider-driven breach rather than malware-based intrusion.
Following disclosure to regulators, South Korean authorities including the Personal Information Protection Commission, police, and KISA opened an investigation, reviewed server logs, and tracked the suspect's IP activity. An emergency government meeting was also convened in response to the scale of the incident.
After discovering the breach, Coupang blocked the unauthorized access path, increased monitoring, and hired an independent security firm to investigate. The company also began notifying affected users and warning them about possible phishing attempts.
Coupang discovered the incident on 2025-11-18 and reported it to relevant South Korean authorities shortly afterward. The company began internal response actions after identifying the unauthorized access.
Coupang later determined that unauthorized access to its customer database started on 2025-06-24. Reports indicate the access may have relied on an authentication key that remained active after a former employee left the company.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
11 references tracked. Mallory keeps watching after this page renders.
csoonline.com
Open sourcesecurityonline.info
Open sourcesecurityaffairs.com
Open sourcegovinfosecurity.com
Open sourcetherecord.media
Open sourcedatabreaches.net
Open sourcebleepingcomputer.com
Open sourcecio.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.