Coupang, South Korea's largest online retailer, suffered a major data breach that exposed the personal information of 33.7 million customers. The breach was traced to a former developer, a Chinese national, who stole the data and attempted to extort the company by threatening to leak the information unless paid. After the breach was discovered, the perpetrator destroyed his laptop, disposed of it in a river, and fled the country. Coupang responded by hiring Mandiant, Palo Alto Networks, and Ernst & Young to assist with the investigation and digital forensics, and worked closely with the South Korean government to secure a confession and recover evidence.
In response to the incident, Coupang announced a $1.2 billion voucher program aimed at restoring customer trust, though critics have argued that the vouchers, redeemable only with Coupang, serve more as a marketing tactic than genuine compensation. The company publicly acknowledged the breach shortly after discovery and has been transparent about its cooperation with authorities and the steps taken to address the fallout. The investigation included the analysis of recovered computing devices and hard drives, which were handed over to government investigators for further examination.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
The breach and Coupang's response prompted congressional hearings and sustained public criticism over corporate responsibility, privacy protections, and the adequacy of compensation. Consumer organizations publicly challenged the company's handling of the incident.
Coupang unveiled a voucher-based compensation plan valued at about $1.2 billion for affected customers. Consumer groups and critics argued the offer functioned more as a marketing program than meaningful compensation because the vouchers were redeemable only on Coupang platforms and could require additional spending.
The breach triggered a leadership shakeup at Coupang's South Korean subsidiary, including the resignation of its CEO and the appointment of an interim leader. The change came as scrutiny intensified over the company's handling of the incident.
Coupang engaged Mandiant, Palo Alto Networks, and Ernst & Young to investigate and respond to the breach, while coordinating with the South Korean government. The company said its investigation concluded the leaker acted alone, deleted the data, and did not share it further.
After stealing the data, the former developer allegedly attempted to extort Coupang, tried to destroy evidence, and fled South Korea. Forensic work later supported the suspect's confession, and investigators recovered relevant hardware including a laptop retrieved from a river.
A former Coupang developer, identified as a Chinese national, exfiltrated customer data affecting 33.7 million people by using a stolen security key. Exposed data included names, email addresses, delivery addresses, and phone numbers; Coupang said payment card and login data were not compromised.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.