Full Breakdown
Coupang's Massive Data Breach: Apologies and Compensation Plan
12/29/2025, 7:58:14 PM
Overview of the Data Breach Incident
Coupang, South Korea's leading e-commerce platform, has announced a compensation package of 1.69 trillion won (approximately $1.18 billion) following a significant data breach that exposed the personal information of around 33.7 million customers. The breach, which was disclosed on November 18, 2025, is considered one of the largest in South Korean history, affecting more than 63% of the country's population.
Details of the Compensation Plan
Coupang's compensation plan includes vouchers worth 50,000 won (about $35) for each affected customer. These vouchers can be utilized across various Coupang services, including its main shopping platform, food delivery, travel offerings, and the luxury beauty platform R.LUX. The company has stated that even former customers who closed their accounts after the breach will be eligible for these vouchers. Customers can check their eligibility starting January 15, 2026.
Official Statements and Responses
Coupang's founder and CEO, Bom Kim, publicly apologized for the breach, acknowledging that the company's initial response was inadequate. He expressed regret for the delay in communication and stated, "In retrospect, this was a poor judgment." Interim CEO Harold Rogers reiterated the company's commitment to customer satisfaction, stating, "The entire staff at Coupang is deeply reflecting on how much concern and distress the recent data breach has caused our customers."
Criticism and Opposition
Despite the compensation announcement, the response has drawn criticism from lawmakers and consumer advocacy groups. Representative Choi Min-hee of the ruling Democratic Party criticized Coupang's decision to offer vouchers tied to its services, suggesting that it trivializes the severity of the breach. Consumer organizations have described the compensation as a marketing tactic rather than genuine restitution, arguing that it fails to address the broader implications of the data leak.
Leadership Changes and Political Scrutiny
The fallout from the breach has led to significant leadership changes at Coupang, including the resignation of CEO Park Dae-jun. Both Kim and Park faced backlash for their absence from parliamentary hearings scheduled to address the breach, which further fueled public outrage. Lawmakers are considering legal actions against Kim, citing his responsibility as the founder of a company that generates 90% of its revenue from South Korea.
Conflicting Reports and Gaps
While Coupang has stated that the data accessed was limited to names, email addresses, phone numbers, and delivery addresses, it has confirmed that payment information was not compromised. However, the details surrounding the breach's timeline and the extent of the data retained by the suspect remain unclear. The company has indicated that a former employee was responsible for the breach, and all stolen data has been recovered.
What's Next
As Coupang navigates the aftermath of this incident, the company faces ongoing scrutiny from both the public and regulatory bodies. Parliamentary hearings are set to continue, and the effectiveness of the compensation plan in restoring customer trust will be closely monitored. The incident has raised critical questions about data security and corporate accountability in South Korea's rapidly evolving digital landscape.
