Radar · Enterprises

Coupang Admits Breach Exposing 33.7 Million Users, Nearly Its Entire Customer Base

Published: Nov 30, 2025
Coupang data breach exposing personal information of 33.7 million users in South Korea
Coupang data breach exposing personal information of 33.7 million users in South Korea

Coupang has admitted the leak of personal information related to 33.7 million users - nearly its entire customer base - after unauthorized access ran undetected for five months, making it one of the largest e-commerce data breaches recorded in South Korea. CEO Park Dae-jun (Park Dae-jun) apologized publicly on Sunday, November 30, 2025, one day after the company formally disclosed the breach.

From 4,500 cases to 33.7 million

Coupang said on Saturday, November 29, that personal data from more than 30 million users had been confirmed leaked - a dramatic escalation from the roughly 4,500 cases first disclosed. With the company reporting 34 million monthly active users, the figures point to near-universal exposure. The breach began on June 24, according to the apology issued by Park, who said he expressed deep regret over the incident and sincerely apologized for causing significant inconvenience and concern to the public.

What leaked and what did not

The exposed information includes names, phone numbers, email addresses and home addresses. Payment details, credit card information and login credentials - which are stored separately - were not accessed, and customers do not need to take account-related measures, the company said. The distinction limits the direct financial risk per user but not the scale of the phishing surface: stolen contact data is precisely the raw material of convincing scam calls and messages.

A five-month blind spot

Server racks standing for the authentication vulnerability that let attackers reach Coupang accounts for five months
Server racks standing for the authentication vulnerability that let attackers reach Coupang accounts for five months

More alarming than the scale are the oversight lapses that allowed unauthorized access to continue undetected for five months. The government's initial findings, released after an emergency meeting in Seoul chaired by Science and ICT Minister Bae Kyung-hoon (Bae Kyung-hoon), state that the attacker exploited an authentication vulnerability in Coupang's servers, gaining access to more than 30 million accounts without a normal login process. The government received Coupang's first report of the attack on November 19 and of the data leakage on November 20, with on-site inspections ongoing since then.

Investigations and the threat of record sanctions

A joint public-private investigative task force was launched on the day of the meeting to determine the cause and craft preventive measures. The privacy watchdog will examine whether Coupang violated personal data protection or safety management obligations, saying strict sanctions will follow if violations are found. The Seoul Metropolitan Police Agency opened a criminal investigation after Coupang formally reported the case. Given the scale, penalties could surpass the 134.8 billion won ($92 million) fine imposed on SK Telecom - the highest privacy-related sanction in the country to date.

A wave of breaches behind it

Warnings and open questions

Authorities urged the public to watch for calls or text messages disguised as coming from Coupang, warning about phishing using terms such as "damage confirmation", "compensation" or "refunds", and declared a three-month period of heightened monitoring across the internet, including the dark web. Industry reports suggest the breach may have originated inside the company, possibly involving a foreign employee who has already left Korea; Coupang listed the suspect as "unidentifiable" in its police filing and said such claims cannot be confirmed, adding that it is cooperating fully with government agencies. For Korean e-commerce, the case is now a benchmark: the question is no longer whether a platform of this size can be breached, but how long a breach can stay invisible.

Leave a comment

Just Published

Partner news digest