Skip to main content
Back to overview
High

Coupang Data Breach: Authentication Failures Expose Customer Data in South Korea

South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January.

Key points

  • Coupang, a major South Korean e-commerce retailer, experienced a data breach from April to November 2026, with a re-access attempt in January.
  • South Korean authorities attributed the breach to authentication vulnerabilities and management failures.
  • The attacker exploited user authentication vulnerabilities to gain unauthorized access to customer accounts.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Hacking · Confidentiality impact

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality

Published
Jul 24, 2026
Updated
Jul 27, 2026
Confidence
High
Evidence
15 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch internet-facing systems, credential abuse and exploit activity.

Business impact

Potential data exposure
Impact area
Confidentiality
Likely asset
User or customer data

Mentioned entities

CoupangData DisclosureSouth Korea South KoreanCoupangApril and NovemberJanuary. South KoreaDeputy Minister for Cybersecurity andNetwork PolicySouth KoreanSouth Korea

Quick context

Questions about this signal

What happened in this signal?

South Korean e-commerce giant Coupang experienced a significant data breach between April and November 2026, with an additional access attempt in January. South Korea's Deputy Minister for Cybersecurity and Network Policy publicly attributed the incident to management failures and authentication vulnerabilities during a press conference on July 24, 2026. The attacker exploited user authentication vulnerabilities to gain unauthorized access to accounts without proper login credentials, leading to a large-scale unauthorized information leak. South Korean authorities emphasized that the breach was not the result of highly sophisticated intrusion techniques, but rather stemmed from fundamental security weaknesses in authentication mechanisms and inadequate security management practices. The breach resulted in large-scale unauthorized access to customer information. The unauthorized access has since been terminated. This incident has also led to a record fine of $422 million by South Korea's Personal Information Protection Commission (PIPC) and ongoing diplomatic discussions between South Korea and the U.S. due to Coupang being an American-owned company operating in South Korea.

When was this signal reported?

Shadow Tier lists Jul 24, 2026 as the signal date.

Which organization is connected to this signal?

Coupang is the organization connected to this public signal.

Explore Coupang
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence