Massive Coupang Breach Exposes 34 Million Users
South Korean e-commerce giant Coupang confirmed over the weekend that a massive data breach active for over five months has exposed the personal information of nearly 34 million customers nationwide.
How the Massive Coupang Data Breach Unfolded
Initially, the e-commerce platform detected unauthorized access to approximately 4,500 user accounts on November 18. However, a subsequent forensic investigation revealed a much larger security failure: the breach actually compromised roughly 33.7 million customer accounts in South Korea. According to company statements, the unauthorized access began on June 24, 2025, utilizing overseas servers to bypass security protocols.
What Customer Information Was Exposed?
The security incident compromised a wide range of customer data. According to Coupang, the leaked information includes:
- Customer names
- Email addresses
- Phone numbers
- Physical shipping addresses
- Specific order histories
Secured Financial and Login Data
Fortunately, Coupang confirmed that highly sensitive financial and security credentials remain unaffected. Crucial data such as payment details, credit card numbers, and account passwords were not accessed during the five-month breach and remain fully secure.
Police Target Former Employee as Key Suspect
In response to the incident, Coupang immediately notified the Korea Internet & Security Agency (KISA), the Personal Information Protection Commission (PIPC), and the National Police Agency. Following a formal complaint filed on November 18, law enforcement authorities reportedly identified a suspect—a former Chinese Coupang employee who is currently located abroad.
No Impact Detected on Regional Markets
While Coupang operates extensively across Asia, a company spokesperson confirmed that the breach appears localized to South Korea. Current evidence indicates that customer databases for Coupang Taiwan and its Japanese food delivery service, Rocket Now, were not impacted. To mitigate further risks, Coupang has blocked the unauthorized access routes, upgraded its internal monitoring protocols, and retained external cybersecurity experts to secure its infrastructure.
A History of Cybersecurity Vulnerabilities
This massive leak is the latest in a series of high-profile cybersecurity incidents impacting South Korea. Coupang itself has struggled with data security in recent years, experiencing past breaches that exposed customer details and leaked delivery drivers’ private information between 2020 and 2021. More recently, in December 2023, a vulnerability in its seller management system compromised the personal information of over 22,000 customers.
