
A knowledge breach at Coupang that uncovered the knowledge of 33.7 million prospects has been tied to a former worker who retained entry to inner programs after leaving the corporate.
This was shared by the Seoul Metropolitan Police Company with native information shops, following an investigation that included a raid on the agency’s places of work earlier this week.
Coupang is South Korea’s largest on-line retailer, using 95,000 individuals and producing annual income of over $30 billion.
On December 1, 2025, the corporate introduced that it had suffered an information breach that uncovered the non-public knowledge of 33.7 million prospects, together with names, electronic mail addresses, bodily addresses, and order data.
The breach occurred on June 24, 2025, however Coupang solely found it on November 18, when it additionally launched an inner investigation.
On December 6, Coupang revealed an replace on the incident, assuring its prospects that the stolen data had not been leaked anyplace on-line.
Regardless of these assurances and the corporate’s claimed full collaboration with the authorities, the police raided the corporate’s places of work on Tuesday to gather proof for an unbiased investigation.
On Wednesday, the corporate’s CEO, Park Dae-Jun, introduced his resignation and apologized to the general public for failing to cease what’s the nation’s worst cybersecurity breach in historical past.
Because the police continued their investigations in Coupang’s places of work for a second day, they uncovered that the first suspect was a 43-year-old Chinese language nationwide who was a former worker of the retail big.
In response to JoongAng, the person, who joined Coupang in November 2022, was assigned to an authentication administration system and left the agency in 2024. He’s believed to have already left the nation.
The Korean information outlet reviews that the police had been nonetheless at Coupang’s places of work yesterday, gathering data corresponding to inner paperwork, logs, system data, IP addresses, person credentials, and entry histories that would assist clarify how the rogue former worker gained entry to the company programs.

Supply: Korea JoungAng Every day
The police have acknowledged that, whereas Coupang is handled because the sufferer, if negligence or different authorized violations are discovered, the corporate and workers answerable for defending buyer knowledge could also be deemed liable.
Within the meantime, the incident has sparked high-volume phishing exercise within the nation, affecting roughly two-thirds of its inhabitants, and the police have obtained lots of of reviews of Coupang impersonation for the reason that begin of the month.
Damaged IAM is not simply an IT drawback – the affect ripples throughout your complete enterprise.
This sensible information covers why conventional IAM practices fail to maintain up with trendy calls for, examples of what “good” IAM appears like, and a easy guidelines for constructing a scalable technique.
