South Korean police are investigating a major Coupang customer data breach impacting roughly 33.7 million (i.e., more than 30 million) accounts, with exposed data reported to include names, email addresses, and other personal details. Authorities indicated the case outline is nearing completion, including the suspected method of access, and are also probing a former Coupang employee believed to have played a key role in the incident.
The investigation has expanded to potential obstruction and evidence tampering tied to Coupang’s internal handling of the breach. Interim/acting CEO Harold Rogers was questioned/summoned multiple times as police examine whether Coupang destroyed or concealed evidence or otherwise disrupted the government inquiry, including scrutiny of whether the company’s own forensic review interfered with law enforcement efforts. Police also recovered a smashed laptop from a river allegedly weighted with bricks, which investigators believe may be connected to attempts to destroy evidence; Coupang has said it is cooperating and has denied negligence and related allegations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Seoul police questioned Coupang Korea interim CEO Harold Rogers as part of an investigation into whether the company destroyed or concealed evidence and whether its internal forensic review interfered with the official probe. Rogers said Coupang would fully cooperate, and reports noted he had previously missed two summonses.
South Korean police said their investigation found that the breach actually affected more than 30 million accounts, with one report putting the figure at 33.7 million. Exposed data included names, email addresses, and other personal information.
In December, South Korean police recovered a smashed laptop from a river that they allege was intentionally destroyed to eliminate evidence related to the Coupang breach investigation. The recovery became part of the broader probe into possible obstruction and evidence tampering.
Coupang disclosed a data breach in November and said its internal investigation found that roughly 3,000 accounts were impacted. The company attributed the incident to a former employee who discarded data from the most accessed accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.