Coupang, South Korea’s largest online retailer, suffered a massive data breach that compromised the personal information of nearly 34 million customers. The breach, which was revealed in mid-November, led to the resignation of CEO Park Dae-jun, who cited a deep sense of responsibility for the incident and its aftermath. Coupang’s parent company appointed Harold Rogers as interim CEO, with a stated focus on restoring customer trust and stabilizing the organization. The breach has intensified scrutiny of cybersecurity practices in South Korea, a country already noted for frequent data security incidents.
In response to the breach, Seoul Metropolitan Police cyber investigators raided Coupang’s headquarters, seizing devices and data to determine the cause and scope of the incident. Authorities believe the perpetrator was a Chinese former employee with privileged access, who allegedly used a stolen private encryption key to forge authentication tokens and access customer data. The incident has sparked political debate over the adequacy of South Korea’s data protection laws and raised concerns among investors, especially after it was revealed that senior executives sold shares in a preplanned sale shortly before the breach was publicly disclosed.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
9 events from the most recent confirmed update back to the earliest known activity.
South Korean regulatory bodies ordered Coupang to revise its terms of service and strengthen user protections following the breach. Officials also discussed tougher penalties and possible record-setting fines tied to the company's security practices.
Following public disclosure of the incident, South Korea saw hundreds of reports of phishing messages impersonating Coupang. The company also faced broader legal and political scrutiny, including reported class-action litigation and criticism of its liability practices.
Amid the fallout from the breach, Coupang CEO Park Dae-jun stepped down and issued a public apology. The company appointed Harold Rogers as interim CEO to lead the response and try to restore customer trust.
Seoul cyber investigators raided Coupang's headquarters and seized devices and data to determine the cause and route of the breach. The raid formed part of a broader criminal investigation into the exposure of 33.7 million customer records.
Investigators traced the breach to a 43-year-old former Coupang employee, a Chinese national alleged to have kept access after leaving the company. Authorities pursued a search warrant and examined how he retained privileged access.
After the breach was disclosed, South Korean police and other authorities began investigating the incident, including whether Coupang had been negligent in protecting customer data. The case also drew scrutiny from lawmakers and senior government officials.
Coupang did not detect the intrusion for nearly five months and discovered the breach on November 18, 2025. The incident was then revealed publicly, triggering a national backlash over the scale of the exposure.
On June 24, 2025, unauthorized access to Coupang systems began, exposing personal data from 33.7 million customer accounts. Reports say the attacker used a stolen private encryption key to forge authentication tokens and access internal systems through overseas servers.
A Chinese national who had worked at Coupang left the company in 2024 but allegedly retained access to internal systems and an internal authentication key, setting the stage for the later breach.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
govinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcetechrepublic.com
Open sourcehackread.com
Open sourcebleepingcomputer.com
Open sourcecnbc.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.