Coupang Data Breach Exposes 33.7 Million Customers for Five Months
E-commerce giant Coupang is facing widespread concern and frustration following the revelation of a massive data breach that compromised the personal information of 33.7 million customers. The U.S.-listed company, based in Seoul, confirmed Saturday that the breach, which exposed nearly its entire user base, had been ongoing for an alarming five months before its discovery.
Scope of the Compromised Data
The compromised data includes sensitive details such as customers' names, phone numbers, email addresses, and delivery addresses. Fortunately, Coupang has stated that critical financial information like payment data, credit card numbers, and login credentials were not affected in this incident.
Timeline of Discovery and Investigation
Investigations reveal that unauthorized access to delivery-related personal information began as early as June 24, with activity traced to overseas servers. Coupang's internal systems detected the breach on November 18, and authorities were promptly notified within two days. Initially, the company reported a smaller incident affecting approximately 4,500 accounts.
However, as the investigation by police, launched after a complaint on Tuesday, deepens, the true scale of the breach has become clear, far exceeding initial estimates and extending much further back in time. This significant escalation has intensified customer anxiety regarding the potential misuse of their exposed personal data.
Precedent and Future Implications
The incident at Coupang dwarfs the scale of previous major data leaks in South Korea, notably surpassing SK Telecom's breach in April, which impacted 23.2 million users and led to a record fine of 134.8 billion won. Experts caution that the full extent of the damage could still grow as the investigation progresses, drawing parallels to incidents like the Lotte Card breach, where initial denials of compromise were later retracted to confirm the exposure of sensitive financial details.