Full Breakdown
Major Data Breach at Coupang: Implications and Investigations
2/10/2026, 8:49:21 PM
Overview of the Incident
In a significant data breach, Coupang, South Korea's largest e-commerce platform, experienced the unauthorized access of personal data from approximately 33.67 million user accounts. The breach, which occurred between April and November 2025, was executed by a former employee who exploited vulnerabilities in the company's user authentication system. The Ministry of Science and ICT has classified this incident as the most severe data breach in the nation's e-commerce history.
Details of the Breach
The former Coupang developer accessed sensitive information, including names, email addresses, phone numbers, and delivery addresses, by forging internal authentication keys. This unauthorized access led to over 140 million views of the company's delivery address list and significant exposure of user data. The investigation revealed that the attacker had previously tested the vulnerabilities in January 2025, indicating a premeditated approach to the breach.
Government Response and Investigations
Following the breach, South Korean authorities launched a comprehensive investigation. The Ministry of Science and ICT criticized Coupang for failing to detect the unauthorized access and for not revoking the signing keys of former employees. The company also delayed reporting the breach beyond the legally mandated 24-hour period, leading to potential administrative penalties. The ministry has requested a corrective action plan from Coupang, and a formal order may follow based on the company's response.
In addition to the ministry's investigation, the police and the Personal Information Protection Commission are conducting separate inquiries into the breach. The police have initiated a criminal investigation into the actions of the former employee, while the commission is assessing the full scope of the data leak and any legal violations.
Broader Implications
The breach has escalated tensions between South Korea and the United States, with U.S. officials expressing concerns over the treatment of American tech companies. The incident has been linked to broader trade issues, including potential tariff increases on South Korean goods. South Korean national security adviser Wi Sung-lac noted that the Coupang situation is affecting key trade and security matters between the two nations.
Criticism and Opposition
Coupang has faced backlash from the public and lawmakers, with accusations of negligence in protecting user data. The company has also been criticized for obstructing the government probe by failing to preserve critical access logs, which were deleted despite a formal order to retain them. This has raised questions about Coupang's commitment to data security and compliance with regulatory requirements.
Official Statements
Coupang has stated that it is cooperating with the ongoing investigations and has emphasized that no payment details or login information were compromised in the breach. The company has also claimed that it notified affected users in accordance with government guidelines.
Verbatim Quotes
- “The attacker exploited user authentication vulnerabilities to access user accounts without a proper login and caused large-scale unauthorised information leaks,” — Ministry of Science and ICT
- “Coupang needs to introduce a detection and blocking system for electronic access cards that do not go through the normal issuance process,” — Ministry of Science and ICT
- “There is no evidence of any secondary harm arising from the Coupang data incident,” — Coupang Statement
What's Next
As investigations continue, Coupang is expected to face scrutiny regarding its data protection practices and compliance with South Korean laws. The outcomes of these investigations may lead to significant regulatory changes in the country's e-commerce sector.
