South Korea’s leading e-commerce platform Coupang has disclosed a sweeping data breach that exposed sensitive information belonging to approximately 33.7 million customer accounts — roughly matching its entire user base. The breach, which reportedly began on June 24, 2025, was only discovered by the company on November 18, 2025, sparking widespread concern over data protection and privacy standards.
What Happened: The Scope of the Breach
According to a public statement, the breach initially came to light when about 4,500 accounts showed evidence of unauthorized access. However, subsequent investigations revealed that personal data for 33.7 million accounts had been compromised.
Exposed information includes full names, phone numbers, email addresses, physical shipping addresses, and order history details. Crucially, the company says that payment information (like credit card data) and login credentials (passwords) were not compromised.
Coupang has already notified relevant authorities, including the national police, the data protection commission, and cyber-security agencies. Affected customers are being informed via email or SMS. The company cautioned users to remain vigilant for phishing attempts or impersonation scams.
This incident is fueling broader scrutiny in South Korea over corporate data-protection practices, regulatory compliance, and internal access management. Authorities have already launched an investigation to determine whether Coupang violated data protection laws.
Expert Views and Broader Implications
Cybersecurity experts observing the fallout call the breach a “wake-up call” for companies handling large volumes of personal data. Insider threats — such as ex-employees with lingering credentials — are often underestimated, yet prove to be among the most dangerous vectors.
In this case, the suspected misuse of access tokens underscores the need for stricter identity and access management (IAM), especially post-employment de-provisioning. For a company of Coupang’s scale, even a single unrevoked token can lead to catastrophic exposure.
On a regulatory level, the incident is likely to accelerate reform in data-protection enforcement. The government’s rapid response — forming a joint investigation team — hints at potential heavier penalties and stricter compliance requirements for large platforms found negligent.
For customers, the risk goes beyond privacy — exposed shipping and contact details can fuel phishing, identity fraud, and even physical scams. Cyber-advisory bodies have already issued alerts recommending users to stay alert for suspicious communications claiming to be from Coupang or related parties.
Conclusion: A Critical Inflection Point
The Coupang breach is more than just a corporate embarrassment — it highlights systemic vulnerabilities in data handling among high-profile digital platforms. For millions of users, days or months of exposure may have left personal information vulnerable to misuse.
As investigations proceed, all eyes will be on how Coupang remediates the breach, compensates affected users, and strengthens its IAM and monitoring systems. For regulators and businesses alike, this episode could mark a turning point for data-protection standards in South Korea’s tech ecosystem.
Please subscribe to the Newsletter so that you do not miss any critical update
