Skip to main content
Breach Signal

Breach report

Retail

Coupang

Korea's Coupang says data breach exposed nearly 34M customers' personal information

South Korea's largest online retailer disclosed that personal data tied to 33.7 million customer accounts, more than half the country's population, had been accessed over five months in 2025, apparently by a former employee using an unrevoked security key.

Reported by TechCrunch

Records exposed

33.7M

33.7 million customer accounts

Scale vs. largest on file

When
2025
How they got in
Insider misuse of retained authentication key by former employee
Sector
Retail

In late November 2025, Coupang, the e-commerce company often described as South Korea's answer to Amazon, revealed that personal information linked to 33.7 million customer accounts in the country had been exposed. The company said unauthorized access began on June 24, 2025, and went unnoticed until November 18, when it detected what first appeared to be a breach affecting about 4,500 accounts. A fuller investigation showed the scope was vastly larger, making it the biggest consumer data breach in South Korean history.

The exposed information included customer names, email addresses, phone numbers, shipping addresses and some order history. Coupang said payment card details and login credentials were not compromised. The breach did not affect its operations in Taiwan or its food delivery service in Japan. The company reported the incident to the Korea Internet & Security Agency, the Personal Information Protection Commission and the National Police Agency.

Police and media reports identified the suspected culprit as a former Coupang employee, a Chinese national who had worked on the company's authentication systems and who allegedly used an internal security key that remained valid after his departure to access customer data. He was reported to have left South Korea. A government-led investigation later concluded that the incident resulted from poor management of authentication systems rather than a sophisticated external attack, a finding that intensified scrutiny of Coupang's internal controls.

The political fallout was severe. Chief executive Park Dae-jun resigned in December 2025, and founder Bom Kim issued a public apology. Police raided Coupang's offices, lawmakers summoned executives to parliamentary hearings, and regulators signaled the possibility of heavy fines under South Korea's privacy law. Coupang announced a compensation package valued at about 1.69 trillion won, issuing vouchers worth 50,000 won per affected customer, but consumer groups and legislators criticized the plan for being redeemable only on Coupang's own services. Lawsuits from affected customers followed in South Korea.

The Coupang breach is a stark example of insider risk and the danger of failing to revoke access when employees leave. It came months after a major breach at SK Telecom and deepened public concern in South Korea about how large platforms protect personal data. For businesses, the lessons included rotating keys and credentials, monitoring for unusual bulk queries and enforcing least-privilege access. Consumers were warned to expect smishing and delivery-themed phishing using their real order details.

More from the wire

More in Retail.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.