South Korean e-commerce giant Coupang has disclosed a significant data breach affecting approximately 33.7 million customers, nearly its entire user base.
The incident represents one of the most substantial known data breaches in South Korea’s history and has triggered an investigation by authorities seeking to determine how the unauthorized access occurred and what steps failed to prevent it.
Scope of Exposed Data
The breach exposed multiple categories of personal information belonging to affected customers. According to Coupang’s official notification, the compromised data includes names, phone numbers, email addresses, shipping addresses, and complete order histories.
This combination of information enables threat actors to conduct targeted phishing campaigns and social engineering attacks against customers.
However, Coupang confirmed that highly sensitive financial data remained protected.
Credit card numbers, payment information, and account passwords were not accessed during the breach, limiting potential fraud risks related to direct financial theft.
The company advised customers that they do not need to reset passwords or discontinue using their accounts. However, Coupang warned users to remain vigilant against phishing messages impersonating the company and attempting to extract additional sensitive information.
Attack Timeline and Discovery
The unauthorized access began on June 24, 2025, but remained undetected for nearly five months. When Coupang first noticed unusual activity on November 18, 2025, the company’s initial assessment suggested that only approximately 4,500 customers had been affected.
A subsequent internal security review revealed the true scale of the incident, exposing the significant gap between initial detection and comprehensive forensic analysis.
The attack has been attributed to a former Coupang employee, specifically a former Chinese national who previously worked on the company’s authentication systems.
The attacker exploited a critical infrastructure failure: cryptographic signing keys were not revoked after the employee’s departure.
These digital cryptographic tools serve as identity verification mechanisms within the system.
Using these unrevoked keys, the attacker allegedly created fraudulent access tokens that enabled unauthorized system access.
These tokens bypassed standard security authentication procedures, allowing the attacker to log in from overseas locations without triggering normal security alerts.
This authentication system bypass represented a fundamental failure in access management protocols.
The Seoul Metropolitan Police Agency is actively investigating the breach, examining Coupang’s server logs and collaborating with international partners to trace the IP addresses used in the attack.
Investigators are also analyzing anonymous emails sent to Coupang containing threats to reveal security vulnerabilities. Notably, these emails made no financial demands, complicating threat attribution efforts.
Coupang faces substantial legal and financial consequences. Under South Korea’s Personal Information Protection Act, regulators can impose fines up to 3 percent of the company’s average annual revenue for data protection violations.
Based on Coupang’s recent financial performance, potential penalties could reach 1 trillion won (approximately $680 million), significantly exceeding the previous record fine of 134.8 billion won in South Korea.
Find this Story Interesting! Follow us on Google News, LinkedIn and X to Get More Instant Updates
%20(1).webp?fit=1600,900&ssl=1)


