Hacker Dumped MacBook into River in Attempt to Destroy Digital Evidence

A former Coupang employee attempted to destroy incriminating evidence by throwing his MacBook Air into a river.

Still, investigators recovered the device and traced it back to the accused using its serial number. The incident exposed the personal data of 33 million South Korean customers.

Coupang, South Korea’s largest e-commerce platform, revealed the breach on Christmas after completing a forensic investigation with Mandiant, Palo Alto Networks, and Ernst & Young.

The alleged perpetrator stole a security key while employed at the company and used it to access customer records containing order histories and building access codes used by delivery personnel.

According to Coupang’s investigation, the attacker accessed data on approximately 3,000 customers using both a personal computer and a MacBook Air.

After media coverage exposed the incident, a desperate attempt to destroy evidence followed. The accused smashed the MacBook Air, placed it in a Coupang canvas bag with bricks, and discarded it in a river.

The destruction attempt ultimately failed. Investigators recovered the laptop from the river and extracted its serial number, which matched the accused’s iCloud account information.

Forensic teams also discovered attack scripts on the recovered PC’s hard drive, providing crucial evidence.

Coupang claims the perpetrator never transferred stolen data beyond these two devices and deleted everything after news reports emerged.

The company’s sworn statements indicate that the damage remained limited relative to the initial breach scope, affecting over half of South Korea’s 52-million population.

The financial impact remains severe. Coupang announced a ₩50,000 ($35) voucher compensation for all 33 million affected customers, totaling $1.17 billion in costs.

South Korea’s government has launched a formal inquiry into Coupang’s security operations, with potential substantial fines expected, given prior regulatory actions against other Korean tech companies.

This incident highlights the critical importance of forensic investigation capabilities and the difficulty of destroying digital evidence, even when physical devices are destroyed.

Law enforcement successfully reconstructed the perpetrator’s activities despite the attempted destruction.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyber Press as a Preferred Source in Google.

AnuPriya
AnuPriya
Any Priya is a cybersecurity reporter at Cyber Press, specializing in cyber attacks, dark web monitoring, data breaches, vulnerabilities, and malware. She delivers in-depth analysis on emerging threats and digital security trends.

Trending News

Related Stories