South Korean e-commerce giant Coupang suffered a major data breach after a former employee stole a security key and accessed the personal information of approximately 33.7 million customers. The perpetrator used both a PC and a MacBook Air to access customer records, including order histories and building access codes, and later attempted to destroy evidence by smashing the MacBook and throwing it into a river. Despite these efforts, investigators recovered the device and linked it to the accused through its serial number. Coupang worked with forensic experts and law enforcement to investigate the breach, and the company has faced criticism over its handling of the incident and the adequacy of its response.
In response to the breach, Coupang announced a compensation plan totaling 1.69 trillion won (about $1.17 billion), offering purchase vouchers to affected customers, including those who closed their accounts after the incident. The company publicly acknowledged its responsibility and expressed regret for the distress caused, while also defending its cooperation with authorities and the thoroughness of its investigation. The compensation scheme, however, has drawn criticism for being limited to Coupang's own services, with some officials accusing the company of leveraging the crisis for business gain. The incident has led to executive changes within Coupang and increased scrutiny from government agencies and the public.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
12 events from the most recent confirmed update back to the earliest known activity.
Coupang said compensation vouchers would start being issued on January 15, 2026. The company framed the payout and related security improvements as part of its effort to restore trust after one of South Korea's largest data breaches.
On December 29, 2025, Coupang announced a compensation package worth about ₩1.69 trillion ($1.17 billion) for roughly 33.7 to 34 million affected users. The plan offers ₩50,000 vouchers to impacted customers, including some former users.
South Korean authorities launched an inquiry into Coupang's operations in response to the breach, with significant fines reportedly expected. Legal and regulatory scrutiny continued alongside police investigation and related litigation.
Amid the breach fallout, Coupang's previous CEO stepped down and Harold Rogers was appointed interim CEO. Company leadership also issued public apologies and pledged to rebuild customer trust.
Coupang stated that the compromised data was recovered from the suspect's devices and that retained data was later deleted after media coverage of the incident. The company said it found no evidence that the information had been moved off the suspect's devices or sold to others.
During the investigation, authorities and forensic teams recovered the MacBook Air from the river and matched it to the suspect, including through device and account evidence such as an iCloud link. They also seized additional storage devices and used them to confirm the breach details.
Following disclosure, Coupang engaged Mandiant, Palo Alto Networks, and Ernst & Young to conduct a forensic investigation under government oversight. The multi-week probe worked to confirm scope, recover evidence, and assess whether data had been exfiltrated or distributed.
In late November 2025, Coupang publicly disclosed the breach and notified South Korean authorities including KISA, the National Police Agency, and the PIPC. The disclosure drew public criticism and regulatory scrutiny because of the scale of the incident.
Coupang discovered the incident in mid-November 2025, according to reporting citing the company's investigation. The discovery triggered a large-scale response involving law enforcement, regulators, and outside incident-response firms.
After the breach activity, the accused allegedly tried to destroy evidence by smashing a MacBook Air and discarding it in a river, while other storage devices were also targeted. This became a key part of the forensic and law-enforcement investigation.
Investigators later determined the suspect viewed or retained more detailed information from roughly 3,000 customers, including order histories and, in some reports, building access codes. Multiple reports said there was no evidence the data was sold or shared onward.
On June 24, 2025, a former Coupang IT employee allegedly began improperly accessing customer records. The breach ultimately affected about 33.7 million accounts and exposed personal data including names, contact details, addresses, and some order information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
7 references tracked. Mallory keeps watching after this page renders.
securityaffairs.com
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourcetechrepublic.com
Open sourcebleepingcomputer.com
Open sourcecybersecuritynews.com
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.