Skip to main content

Company intelligence

Coupang cybersecurity incidents and threat signals

coupang.com

Coupang logo

Coupang is a US-headquartered technology company operating commerce, delivery, food, streaming and financial-service platforms.

Company country

United States

Facts last verified July 23, 2026

3

Published signals

currently linked to this company

1

Last 28 days

recent published signals

1

Last 90 days

recent published signals

1

High or critical

confidence classifications

July 27, 2026

Latest report

most recent published signal

Explore related intelligence

Explore this reporting from another angle

Based on all published signals currently linked to Coupang. Affected countries come from victim data; the company country above remains a separate profile fact. Counts describe this reporting set, not overall incident prevalence.

Company signals

All published signals involving Coupang

Coupang logoUse of stolen credentials or exploit
High

Coupang Data Breach: Authentication Failures Expose Customer Data in South Korea

South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January. South Korea's Deputy Minister for Cybersecurity and Network Policy publicly attributed the incident to management failures and authentication vulnerabilities during a press conference on July 24, 2026. The attacker exploited user authentication vulnerabilities to gain unauthorized access to accounts without proper login credentials, leading to a large-scale unauthorized information leak. South Korean authorities emphasized that the breach was not the result of highly sophisticated intrusion techniques, but rather stemmed from fundamental security weaknesses in authentication mechanisms and inadequate security management practices. The breach resulted in large-scale unauthorized access to customer information. The unauthorized access has since been terminated. This incident has also led to a record fine of $422 million by South Korea's Personal Information Protection Commission (PIPC) and ongoing diplomatic discussions between South Korea and the U.S. due to Coupang being an American-owned company operating in South Korea.

Coupang
Coupang logo
Medium

Coupang Data Breach Probe and Police Raid

South Korean e-commerce giant Coupang disclosed a significant data breach affecting approximately 33.7 million customers. On December 8, 2025, Seoul Police reportedly raided Coupang Headquarters as part of a probe into the data breach. Exposed data included names, email addresses, phone numbers, and shipping addresses.

Coupang
Coupang logo
Medium

Coupang Data Breach Exposes 33.7 Million Customer Accounts

South Korea's largest e-commerce platform, Coupang, disclosed a data breach that exposed personal information of approximately 33.7 million user accounts. The breach, attributed to a former employee who exploited unrevoked authentication keys, involved names, email and postal addresses, phone numbers, and order histories. No financial information or passwords were compromised. The incident led to a record fine from the Korean Personal Information Protection Commission (PIPC) and an investigation by South Korean authorities. Coupang initially released a statement on November 29, 2025, confirming unauthorized exposure of approximately 4,500 accounts, with a broader admission of 33.7 million accounts on November 30, 2025.

Coupang

FAQ

Questions about Coupang cybersecurity reporting

What does the Coupang page include?

It combines a reviewed organization profile with all current published Shadow Tier signals explicitly linked to Coupang.

Does every mention of Coupang appear here?

No. A signal must contain a reliable company connection and meet the publication criteria; incidental or ambiguous mentions are excluded.

Why can the incident count change?

The page follows current published reporting. Counts change as new evidence is added, classifications are reviewed, or older signals leave the reporting window.