Cyber Incident Victim: Coupang Inc.
Date:
Nov 2025
Location:
South Korea
Summary
Coupang disclosed a data breach that exposed personal information of tens of millions of customers, prompting South Korean regulators to launch multiple investigations and impose a record fine exceeding $400 million. The breach prompted the company to offer compensation vouchers worth over $1 billion to affected users and to cut thousands of logistics jobs as order volumes fell. Investigations revealed that a former employee had accessed data from millions of accounts but retained only a few thousand records, prompting the company to retrieve devices, including a laptop recovered from a Chinese river after a government‑directed operation. Concurrently, U.S. investors filed class‑action lawsuits alleging securities violations, while lawmakers in both countries raised concerns about the impact on bilateral trade and security relations.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
The incident began in November 2025 when Coupang disclosed that a former employee, a Chinese national, had stolen an internal security key and gained unauthorized access to customer data. The breach was first detected on November 18, 2025, and the company later filed a Form 8‑K with the U.S. Securities and Exchange Commission on December 16, 2025, stating that it had activated its incident‑response procedures, blocked the threat actor’s access, reported the incident to Korean regulators and law‑enforcement agencies, and notified affected customers. According to Coupang’s own investigation, the former employee accessed data tied to approximately 33 million to 34 million user accounts but retained personal information from only about 3 000 of those accounts, which included names, phone numbers, delivery addresses, email addresses and order histories; the company asserted that no payment data, login credentials or individual customs numbers were compromised and that the retained data was not distributed or sold externally.

Following the disclosure, South Korean authorities launched a sweeping response. The Personal Information Protection Commission launched an investigation that eventually led to a fine of 624 billion South Korean won, equivalent to over 400 million U.S. dollars, imposed on June 11, 2026, which the commission described as the maximum penalty allowed under the law. In addition, Coupang faced forty separate investigations from eleven different South Korean agencies, threats of travel bans for its executives and the possibility of fines amounting to up to ten percent of its global revenue. The company’s founder, Bom Kim, and interim CEO Harold Rogers were summoned for questioning by the National Assembly; Kim declined to attend hearings in South Korea, citing his role as a global chief executive, and Korean police requested that immigration authorities notify them if he entered the country.
The investigation took an unusual turn when South Korea’s National Intelligence Service allegedly instructed Coupang to recover a laptop that the suspect had thrown into a river in Shanghai after confessing to the theft. According to a House Judiciary Committee report, the NIS told Coupang that its own agents could not operate in China due to legal restrictions, so it directed the company to send one of its own employees to Shanghai to meet the suspect and his lawyer, retrieve a desktop computer, four hard drives, copies of data, a graphics card and a signed confession, and to recover the missing laptop. Coupang complied, hiring a scuba‑diving team to retrieve the laptop from the river on December 17, 2025. The recovered devices, the confession and the suspect’s fingerprints were handed over to an NIS officer at the Korean consulate in Shanghai, after which the NIS denied any involvement in the operation. Coupang’s interim CEO later told congressional officials that he would not have authorized the employee’s trip to China or the hiring of a dive crew unless he believed the company had a legal obligation to comply with the NIS’s directives.
In the aftermath, Coupang announced a compensation plan on December 29, 2025, offering 1.69 trillion South Korean won—approximately 1.17 billion U.S. dollars—in purchase vouchers of 50 000 won each to the 34 million users affected by the breach, including former customers who had closed their accounts. The company stated that the move was a responsible measure for its customers and that it would fulfill its responsibilities to the end. Coupang also said that cybersecurity experts who reviewed the breach concluded it was minor in nature and did not result in harm to customers, a claim that South Korean regulators disputed, noting that the joint public‑private investigation had not yet confirmed the company’s assertions.
The breach and the government’s response triggered broader repercussions. South Korean officials linked the dispute to wider trade and security tensions with the United States, citing the incident as a factor in discussions about tariffs, nuclear‑powered submarine cooperation and intelligence sharing. U.S. lawmakers, including members of the House Judiciary Committee, accused South Korea of launching a “whole‑of‑government assault” on Coupang and warned that the matter was affecting the alliance. Several U.S. investment firms that hold Coupang shares filed notices of intent to pursue arbitration under the U.S.–Korea free‑trade agreement, alleging that Seoul’s enforcement response was disproportionate compared with penalties imposed on Korean companies involved in similar breaches. Meanwhile, Coupang reported a decline in daily active users and payment volume after the breach, while rival platforms such as SSG.com and Market Kurly experienced increased order volumes as customers shifted their spending. The company also reduced its logistics workforce, placing more than 6 000 workers on unpaid leave and cutting hiring as order volumes fell.
