Coupang Admits Breach Exposing 33.7 Million Users, Nearly Its Entire Customer Base
Coupang has admitted the leak of personal information related to 33.7 million users - nearly its entire customer base - after unauthorized access ran undetected for five months, making it one of the largest e-commerce data breaches recorded in South Korea. CEO Park Dae-jun (Park Dae-jun) apologized publicly on Sunday, November 30, 2025, one day after the company formally disclosed the breach.
From 4,500 cases to 33.7 million
Coupang said on Saturday, November 29, that personal data from more than 30 million users had been confirmed leaked - a dramatic escalation from the roughly 4,500 cases first disclosed. With the company reporting 34 million monthly active users, the figures point to near-universal exposure. The breach began on June 24, according to the apology issued by Park, who said he expressed deep regret over the incident and sincerely apologized for causing significant inconvenience and concern to the public.
What leaked and what did not
The exposed information includes names, phone numbers, email addresses and home addresses. Payment details, credit card information and login credentials - which are stored separately - were not accessed, and customers do not need to take account-related measures, the company said. The distinction limits the direct financial risk per user but not the scale of the phishing surface: stolen contact data is precisely the raw material of convincing scam calls and messages.
A five-month blind spot
More alarming than the scale are the oversight lapses that allowed unauthorized access to continue undetected for five months. The government's initial findings, released after an emergency meeting in Seoul chaired by Science and ICT Minister Bae Kyung-hoon (Bae Kyung-hoon), state that the attacker exploited an authentication vulnerability in Coupang's servers, gaining access to more than 30 million accounts without a normal login process. The government received Coupang's first report of the attack on November 19 and of the data leakage on November 20, with on-site inspections ongoing since then.
Investigations and the threat of record sanctions
A joint public-private investigative task force was launched on the day of the meeting to determine the cause and craft preventive measures. The privacy watchdog will examine whether Coupang violated personal data protection or safety management obligations, saying strict sanctions will follow if violations are found. The Seoul Metropolitan Police Agency opened a criminal investigation after Coupang formally reported the case. Given the scale, penalties could surpass the 134.8 billion won ($92 million) fine imposed on SK Telecom - the highest privacy-related sanction in the country to date.
A wave of breaches behind it
- The SK Telecom hack in April compromised USIM server data for 23 million users.
- All three major mobile carriers have reported breaches since then.
- Lotte Card disclosed unauthorized access concerning more than 200 gigabytes of customer information affecting nearly 3 million people.
Warnings and open questions
Authorities urged the public to watch for calls or text messages disguised as coming from Coupang, warning about phishing using terms such as "damage confirmation", "compensation" or "refunds", and declared a three-month period of heightened monitoring across the internet, including the dark web. Industry reports suggest the breach may have originated inside the company, possibly involving a foreign employee who has already left Korea; Coupang listed the suspect as "unidentifiable" in its police filing and said such claims cannot be confirmed, adding that it is cooperating fully with government agencies. For Korean e-commerce, the case is now a benchmark: the question is no longer whether a platform of this size can be breached, but how long a breach can stay invisible.
Just Published

European housing prices and rents

Schneider–PTC: the industrial data integration test behind the deal

Avio USA starts work on its Virginia manufacturing site

One equity market, two currency measures

Russia’s draft budget raises spending and borrowing plans

Russia Sets the 2027 Minimum Wage at 28,935 Rubles, Up 6.8%, on the Way to 35,000 by 2030
Partner news digest
Qatar LNG expansion: readiness, financing and the production test
Pennon’s capital plan: turning finance into better water outcomes
Italy’s diesel relief gap: taxes, price ceilings and implementation
EU–China hybrid trade: from understanding to measurable implementation
Schneider–PTC: the industrial data integration test behind the deal
IKEA’s hybrid resale model: buyback, marketplace liquidity and furniture logistics
Banking AI beyond the ranking: capability, execution and evidence of value
Fishing labour beyond the product label: practical protection
Rhenus and the Middle Corridor: terminals need coordinated connections
Royal Mail restructuring: the test is reliable delivery
Fuel Finder on Google Maps: when price transparency becomes useful competition
Samsung’s memory profit surge: what the preliminary record explains
Leave a comment