In 2025, Coupang, a South Korea-based e-commerce company, experienced a data breach. The incident, which involved a former employee accessing data using an unrevoked signing key, occurred on June 24, 2025, was detected between November 17-14, 2025, and publicly reported on December 1, 2025. The Korean government, specifically the Ministry of Science and ICT, confirmed the findings on February 10, 2026, following a joint investigation.
The breach affected approximately 33.67 million user accounts. The confirmed data types exposed include full names, email addresses, phone numbers, physical addresses, order details, and anonymized apartment entry passwords. While payment information, passwords, or financial/SSN/medical data were not exposed, the incident involved broader access than initially claimed by Coupang, with delivery list pages and order list pages being accessed numerous times. The exact number of unique individuals affected by the delivery and order list access remains unclear, as accounts could store multiple addresses.
More details regarding the breach may emerge as investigations continue. Notices to affected individuals may also be delayed.