Search
Close this search box.
Joint Investigation Reveals Massive Coupang Data Breach Exposing 33.6 Million Accounts

Seoul: A joint public-private investigation has uncovered a significant data breach at Coupang Corp., the South Korean unit of the U.S.-listed e-commerce giant, with over 33.6 million accounts exposed, according to the Ministry of Science and ICT. This revelation starkly contrasts with Coupang's initial claim that only around 3,000 accounts had been compromised, suggesting an attempt to downplay the incident.

According to Yonhap News Agency, the Ministry of Science and ICT reported that Coupang failed to promptly report the breach, violating existing regulations. Choi Woo-hyuk, director general of the ministry's cybersecurity bureau, emphasized during a press briefing that the incident constitutes a major breach involving South Korea's leading online commerce platform.

The ministry plans to impose a fine on Coupang for the delay in reporting the breach and intends to launch a formal investigation into the matter. The joint probe was initiated following Coupang's admission of a massive data breach in November, which exposed personal information such as names, phone numbers, email addresses, and delivery details, potentially affecting the majority of its user base.

Coupang's initial investigation claimed that data from only 3,000 accounts had been leaked, a statement met with public criticism and labeled as "ill-intended" by the science ministry. Recently, Coupang disclosed an additional data leak affecting over 165,000 customer accounts, though the joint probe's findings do not include these newly reported accounts.

As one of South Korea's most popular shopping platforms, Coupang's data breach potentially impacts approximately two-thirds of the country's population. The probe analyzed 25.6 terabytes of web access logs, revealing that 33.67 million users' names and email addresses were compromised.

The investigation determined that hackers accessed Coupang's servers by exploiting a vulnerability in its authentication system, a lapse attributed to management oversight rather than a sophisticated attack.

Despite identifying the breach's cause and scope, the investigation did not delve into the involvement of a former Coupang employee suspected of orchestrating the breach, as this falls under police jurisdiction.

No evidence has been found of the leaked data appearing on dark web platforms. The ministry criticized Coupang for reporting the breach late, noting that the company became aware of the incident on November 17 but did not inform authorities until November 19, violating the 24-hour reporting requirement.

The ministry intends to impose fines on Coupang for this delay and has requested a separate investigation into the company's failure to preserve critical evidence, including missing web access records from a five-month period in 2024 and application access records from late May to early June 2025.

Lastly, the government will require Coupang to submit measures to prevent future data breaches and will inspect their implementation in the coming months.

ADVERTISEMENT