Seoul: A joint public-private investigation has confirmed that a staggering 33.6 million accounts were compromised in a data breach at the South Korean unit of U.S.-listed e-commerce giant Coupang Inc., surpassing the company's initial report of only 3,000 affected accounts, according to the Ministry of Science and ICT.
According to Yonhap News Agency, Coupang Corp., the local unit, failed to promptly report the data breach, which included the exposure of personal information such as names, phone numbers, email addresses, and delivery details. This incident, affecting nearly all of Coupang's user base, raises concerns about the company's transparency and compliance with data protection regulations.
Director General Choi Woo-hyuk of the ministry's cybersecurity bureau stated that the breach represents a major incident involving the country's leading online commerce platform. The investigation was conducted thoroughly and fairly, with results disclosed transparently based on substantial evidence and factual data.
The ministry plans to impose fines on Coupang for the delayed reporting and initiate a formal investigation due to the company's failure to preserve critical evidence. Despite a request to maintain key data, Coupang reportedly lost web access records for five months in 2024 and application access records from late May to early June of 2025.
Coupang initially claimed that only 3,000 accounts were compromised, which drew public criticism. The joint probe revealed that 33.67 million users had their names and email addresses leaked, with potential further exposure due to shared entrance door passwords on the delivery section of Coupang's website.
The attackers exploited vulnerabilities in Coupang's authentication system, forging digital passes to bypass normal security protocols. While the probe did not investigate a former employee suspected to be behind the breach, it highlighted the need for Coupang to enhance its monitoring of abnormal access and implement stronger security measures.
Coupang asserts that no secondary damage has resulted from the breach and maintains that the viewed data does not equate to stolen data. The company confirmed that the exposed data did not include financial or highly sensitive information, emphasizing that there has been no dark web activity related to the incident.
The Ministry of Science and ICT will enforce measures to prevent future breaches and inspect Coupang's compliance with these measures. In response, Coupang has expressed its commitment to cooperate fully with the investigation and take necessary actions to safeguard user information.