Coupang data leak grows to 33.7 million accounts
- Coupang’s data leak has expanded to 33.7 million customer records.
A massive data leak at Coupang has grown to 33.7 million exposed customer records, affecting about three out of four adults in South Korea. The figure has raised concern not only because of the number itself, but because the company had already been fined for past data incidents.
Officials say the attack took advantage of a weakness in Coupang’s authentication system. During a briefing on Sunday, Minister of Science and ICT Bae Kyung-hoon said investigators found that “the attacker exploited an authentication vulnerability in Coupang’s servers and accessed more than 30 million customer accounts – including names, email addresses, delivery addresses and phone numbers – without logging in.” He said a joint task force has been formed to examine the case and review whether Coupang failed to follow rules on protecting personal information.
Authorities traced suspicious activity back to June 24. The access came from overseas servers and continued for months.
Coupang has said it “blocked the access route that a third party used” once the issue was confirmed. But the company’s slow detection and shifting statements have left customers uneasy. When Coupang first disclosed the problem on November 20, it said only 4,500 accounts were affected. It took almost 10 days before the company updated the figure to 33.7 million.
The final number is larger than Coupang’s own active customer base. In its third-quarter report, the company listed 24.7 million active customers in its product commerce business. It also exceeds the largest previous data exposure to be fined in Korea – the SK Telecom case that involved 23.24 million records and a 134.8 billion won penalty.
The incident is drawing more scrutiny because the breach appears to have come from inside the company. Coupang said on November 20 that it had found no signs of an external intrusion. Local media later reported that a former employee with Chinese nationality was being investigated.
“I sincerely apologise for causing the public significant inconvenience and concern,” CEO Park Dae-jun said on Sunday. “I cannot comment because it concerns an ongoing investigation. The matter will become clear through the investigation.”
Coupang has about 10,000 office employees, but only a limited group of IT and systems workers are allowed to view customer records. The company said it tried to tighten its structure by assigning separate executives as chief information security officer and chief privacy officer. Even so, experts say an internal threat can bypass layers of technical protection if access controls are weak.
“We would have assumed that Coupang’s data protection was thorough, since the company has been hiring expensive IT personnel,” one industry insider said. “But customer data protection is the basic of basics. I’m not sure if they even managed access rights properly.”
Others pointed to the same issue. “If this breach occurred through an employee, it indicates that internal security management did not function adequately,” said Park Choon-sik, a cybersecurity professor at Seoul Women’s University. “Insider-related incidents can produce more significant damage than external attacks.”
Coupang’s track record adds weight to the criticism.
- In 2021, an update to its app exposed the names and delivery addresses of 14 customers for about an hour.
- From 2020 to 2021, the names and phone numbers of about 135,000 Coupang Eats drivers were passed to restaurants.
- And in late 2023, the seller system revealed the personal details of more than 22,000 customers.
Together, those missteps led to roughly 1.6 billion won in fines and penalties. During the same period, Coupang’s revenue passed 41 trillion won and continued to climb, while spending on information security grew at a slower rate.
KISA said Coupang allocated about 89 billion won to cybersecurity this year, which amounts to 4.6% of its total IT budget. Although the company increased its security spending in absolute terms, the share of its IT budget used for security has dropped each year: 7.1% in 2022, 6.9% in 2023, and 5.6% last year.
When compared with other major tech firms, Coupang also invests a smaller share of revenue in security. Last year, it spent about 0.2% of revenue on security, while Kakao and SK Telecom were near 0.7%, and Naver and KT were at about 0.4%.
“Cybersecurity requires consistent investment rather than temporary spending following an incident,” Park said. “Security spending functions as an investment. Coupang needs to increase its cybersecurity budget and reinforce internal security awareness.”
Other researchers said spending only solves part of the problem. “The government can strengthen standards, but companies must implement their own countermeasures to address vulnerabilities,” said Youm Heung-youl from Soonchunhyang University. “The investigation needs to identify the exact cause of the problem and establish clear measures to address it.”
Want to discover how IoT is transforming telecoms and connectivity? Join the IoT Tech Expo in Amsterdam, California, and London. Explore how innovations in 5G, edge computing, and IoT are shaping the future of networks and services. The event is part of TechEx and co-located with other leading technology conferences, click here for more information.
Telecoms News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.
TNG – Latest News & Reviews

