South Korean authorities attributed Coupang’s large-scale customer data leak to management and security control failures, not a sophisticated external cyberattack. Investigators said a former Coupang engineer who knew about weaknesses in the company’s authentication process gained unauthorized access beginning in April (after an earlier attempt in January) and maintained access until November, exploiting authentication vulnerabilities to access user accounts without proper login. Officials urged Coupang to remediate security weaknesses and asked police to investigate allegations that Coupang deleted some data despite an order to preserve it; Coupang said it is strengthening safeguards and claimed there was no evidence other parties accessed or viewed the data, and that the exposed data did not include payment or login information.
The incident affected roughly 33.7–34 million customers, with exposed data reported to include names, email addresses, phone numbers, shipping addresses, and some order history. The breach has escalated into a cross-border legal and political dispute: multiple U.S. investment firms (including Greenoaks, Altimeter, Abrams Capital, Durable Capital Partners, and Foxhaven Asset Management) filed notices seeking investor–state dispute settlement (ISDS) arbitration under the Korea–U.S. Free Trade Agreement, alleging South Korea’s investigation and enforcement actions were discriminatory and unusually severe compared with other domestic breach cases; reported measures included threats of major fines, operational suspension, and executive travel bans.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
The unauthorized activity persisted from April through November, and Coupang later said the former employee's program generated about 140 million queries during the incident.
According to the Science Ministry's findings, the former employee began sustained unauthorized access in April, generating fake login tokens with a stolen signing key to access customer accounts without proper authentication.
Foxhaven Asset Management, Abrams Capital, and Durable Capital Partners joined earlier investors seeking investor-state dispute settlement arbitration under the Korea-U.S. Free Trade Agreement over South Korea's handling of the Coupang breach probe. South Korea's Ministry of Justice said the filing triggered a mandatory 90-day consultation period before arbitration could proceed.
The ministry accused Coupang of deleting some data despite a preservation order, asked police to investigate the company, and said it planned an administrative fine of up to 30 million won for reporting the incident to authorities more than 53 hours after internal reporting.
South Korea's Science Ministry released initial findings concluding the breach was caused by management and security control failures, not a sophisticated cyberattack. Officials said about 33.7 million customers' personal data was exposed and criticized Coupang for failing to invalidate the former employee's signing key after departure.
South Korean officials said a former Coupang engineer first attempted to access customer accounts in January by exploiting weaknesses in the company's authentication process and misuse of a signing key.
In December, Coupang disclosed that a cyber incident lasting more than five months exposed personal information tied to nearly 34 million customers in South Korea, including names, shipping addresses, and contact details. The company said payment information and passwords were not exposed.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcedatabreaches.net
Open sourcetechcrunch.com
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.