Seoul: A joint public-private probe into a significant data breach at the South Korean unit of U.S.-listed e-commerce giant Coupang Inc. has confirmed that over 33.6 million accounts have been exposed, the science ministry announced Tuesday. This revelation suggests that Coupang may have initially downplayed the incident by claiming only about 3,000 accounts were compromised.
According to Yonhap News Agency, Coupang Corp., the South Korean unit, failed to report the breach promptly despite existing regulations, as noted by the Ministry of Science and ICT. The ministry intends to fine the company for the delayed report and initiate a formal investigation, emphasizing that Coupang did not preserve vital evidence despite earlier requests.
The joint probe followed Coupang's report of a massive data breach in November, which exposed personal information, including names, phone numbers, email addresses, and delivery details, seemingly affecting nearly all users of the platform. Initially, Coupang cited its investigation, claiming that data from only 3,000 accounts had been leaked, leading to public criticism for what the ministry termed "ill-intended" and unfounded claims.
On Thursday, Coupang disclosed an additional data leak involving more than 165,000 customer accounts. However, the ministry clarified that the joint probe's outcome did not encompass these newly reported accounts.
Coupang, known for its overnight delivery of groceries and daily necessities, is a leading shopping platform in South Korea, with the breach potentially impacting about two-thirds of the country's entire population. The probe analyzed 25.6 terabytes of web access logs, revealing that 33.67 million users' names and email addresses were leaked from the company's system. The ministry noted the delivery section of Coupang's website had been viewed approximately 148 million times, with exposed information including shared entrance door passwords.
The breach's impact may extend further, as Coupang account holders can have goods delivered to family members and acquaintances by entering their names, phone numbers, and addresses. The joint probe team stated that hackers gained access to Coupang's servers by exploiting vulnerabilities in its authentication system. By forging digital passes validated by the company's servers, they bypassed normal authentication procedures.
The science ministry plans to impose fines on Coupang for reporting the breach to authorities after the stipulated 24-hour period. Coupang became aware of the breach at 4 p.m. on Nov. 17 but reported it only at 9:35 p.m. on Nov. 19. Under the law, such delays can result in fines of up to 30 million won (US$20,560).
Furthermore, the ministry will call for a separate investigation into Coupang for failing to preserve evidence, noting the absence of web access records for a five-month period in 2024 and application access records from late May to early June of 2025. The government will instruct Coupang to submit measures to prevent future data breaches this month and will inspect their implementation from June to July.