Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
The Finance Base
Consumer Protection

Coupang Data Breach: What the 33.7 Million-Record Exposure Means for Customers

The Coupang breach involved millions of user records, delivery details and some building-entry codes. Here is what Korean authorities found, how it differs from Coupang’s account, and what customers should do.

By TheFinanceBase Team 6 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Yes—the 2025 Coupang incident was a major personal-information breach. Korean authorities identified 33,673,817 exposed user records and later described approximately 33.22 million affected Coupang users plus information on about 4.33 million additional people in shipping records. Those figures count different datasets and are not proof that 33.7 million unique people had every item of data exfiltrated. Names, contact details, addresses, order information and, in some cases, building-entry codes were exposed. Coupang says banking, payment-card and login credentials were not compromised, but its account of the amount retained differs sharply from subsequent government findings.

What happened in the Coupang breach?

According to South Korea’s Personal Information Protection Commission (PIPC), a former Coupang employee accessed authentication signing keys while employed, later forged backup authentication tokens and used them to reach internal pages between April and November 2025. The commission characterized the incident as a failure of basic security management rather than an unusually sophisticated attack. The findings concern Coupang’s Korean operations and related Korean data subjects.

PIPC said the employee’s access was enabled by plaintext signing keys, a backup key that was not promptly revoked after departure, excessive reliance on token-based authentication, weak controls for abnormal access, inadequate traffic analysis and deficient log management. Some logs were automatically deleted despite preservation obligations, limiting investigators’ ability to reconstruct the full scope.

Coupang said it detected unauthorized access around November 17, 2025, disabled it, reported the incident and notified potentially affected customers. South Korea’s joint investigation began on November 30, 2025, involving the Ministry of Science and ICT, KISA and other authorities.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The available official findings identify former-employee misuse enabled by control failures. They do not establish that all Coupang systems were breached, that all exposed information was downloaded, or that the information was sold or publicly posted.

How many customers or records were affected?

“33.7 million customers” is a shorthand, not one definitive count of unique people. Authorities and Coupang measured different pages, records, accounts, access events and data subjects.

Figure What it measures How to interpret it
33,673,817 User-information records identified in the government’s investigation of the “Edit My Information” page A record count, not necessarily 33,673,817 unique individuals
Approximately 33.22 million Coupang users described by PIPC as affected A government estimate using its affected-user analysis
Approximately 4.33 million Additional third-party data subjects in shipping information May include recipients, relatives, acquaintances and others who were not Coupang members
Approximately 33.76 million Records accessed on the personal-information edit page in the joint investigation An access-related figure, not proof that every record was downloaded or retained
About 140 million Accesses to delivery-address-list pages Access events, not people
About 50,000 Accesses to delivery-address-edit pages Access events, not people
About 100,000 Accesses to order-history pages Access events, not people

Adding PIPC’s 33.22 million users and 4.33 million third-party subjects suggests a combined scale of roughly 37.55 million data subjects, but that arithmetic must not be presented as 37.55 million unique customers. The categories can overlap, and shipping records do not represent customer accounts.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

The government’s February findings are reported in its policy briefing, with technical scope details in the Ministry of Science and ICT release and PIPC’s June decision.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What information was exposed?

The confirmed or reported categories include:

  • Names
  • Email addresses
  • Telephone numbers
  • Delivery addresses
  • Order histories or recent-order information
  • Shipping details belonging to non-member third parties
  • Building-entry or 공동현관 access codes in some delivery-address information

Building-entry codes create a physical-security concern distinct from ordinary marketing-data exposure. A person whose address or entry code appeared in an order may face risk even if they never held a Coupang account.

In its U.S. regulatory disclosure, Coupang said customer banking information, payment-card information and login credentials were not obtained or compromised. That is Coupang’s disclosed assessment, not a finding that every form of fraud risk disappeared. Addresses, order details and compensation notices can support phishing, impersonation, delivery scams or unwanted physical contact.

Rank #3
Sale
Yubico - YubiKey 5 NFC Bundle (USB-A + USB-C) - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB or NFC, FIDO Certified - Protect Your Online Accounts
  • Works with 1000+ Accounts: It’s compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more.
  • Fast & Convenient Login: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required.
  • Most Secure Passkey: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • Built to Last: Made from tough, waterproof, and crush-resistant materials. Made in Sweden with the highest security standards.
  • Yubico Authenticator App: Compatible with the safest authenticator app experience across mobile and desktop.

Sources: Coupang’s SEC filing and PIPC’s findings.

Coupang’s account versus the government’s findings

Question Coupang’s disclosed position Government or PIPC position
Accounts or records accessed About 33 million accounts Large-scale exposure across multiple pages and datasets, including 33,673,817 identified records
Data retained Information from approximately 3,000 accounts was saved, then deleted, and not shared with third parties Authorities identified a much broader leak of personal information and third-party shipping data; the retained-data assertion was not treated as the complete impact assessment
Payment information Banking and payment-card information was not compromised No cited official finding in the supplied decisions contradicts that specific statement
Cause Unauthorized access by a former employee Former-employee misuse enabled by inadequate key, token, access-control and monitoring practices
Logs Internal investigation and forensic review Deleted or inadequately preserved logs impaired the investigation
Severity Limited retained data, according to Coupang Serious, large-scale personal-information exposure

Coupang’s December disclosures are available in its SEC filing and its company update. “Accessed,” “retained” and “distributed” are different events: evidence of one does not automatically prove the others.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Timeline of the incident and response

Date Event
June–November 2025 PIPC says forged authentication tokens were used to access internal pages.
November 17, 2025 Coupang said it became aware of unauthorized access around this period.
November 20, 2025 Coupang reported the incident affecting more than 33 million users, according to PIPC.
November 30, 2025 Joint government investigation began.
December 8–18, 2025 Coupang conducted an internal investigation, according to PIPC.
December 24–28, 2025 Coupang said about 33 million accounts were accessed but data from about 3,000 was retained.
January 15, 2026 Start date announced for Coupang’s voucher compensation program.
February 10–11, 2026 Authorities published joint-investigation findings, including the 33,673,817-record figure and deleted-log concerns.
June 10–18, 2026 PIPC resolved sanctions and published its English-language decision.
June 12, 2026 PIPC announced resumed collective dispute-resolution proceedings.
August 18, 2026 Current status: sanctions announced; implementation, appeals, dispute resolution and further litigation remain subject to developments.

Penalties and legal consequences

On June 10, 2026, PIPC imposed a KRW 624.681 billion administrative penalty on Coupang, a KRW 16.8 million administrative fine, and correction and publication orders. It separately imposed a KRW 248 million penalty on Coupang Fulfillment Services for other privacy violations. The official amounts are denominated in Korean won; they are not customer payouts or criminal fines.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The English PIPC release uses “penalty,” while Korean materials describe the measure using Korean administrative-surcharge terminology. The decision cites failures involving authentication-key management, access controls, anomaly monitoring, breach notification, notification of some non-members, log preservation, privacy governance and the chief privacy officer’s role. See the Korean sanction summary and English PIPC release.

PIPC also resumed and combined collective dispute-resolution proceedings in June. That process is not a completed class-action judgment and does not guarantee compensation for every affected person. The official announcement is at PIPC’s dispute-resolution notice.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What compensation did Coupang announce?

Coupang announced a customer-compensation program worth approximately KRW 1.685 trillion, described mainly as purchase vouchers, with a scheduled start date of January 15, 2026. The company stated an approximate value of $1.2 billion using its own conversion in its filing.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

The available official materials establish the program’s announced scale and start date, but not a complete current statement of eligibility, expiration, redemption across Coupang services, treatment of former customers or any cash-equivalent option as of August 18, 2026. Customers should rely on authenticated Coupang notices for those operational terms. The program is a company-announced remedy, not the KRW 624.681 billion regulatory penalty converted into payments to users.

What affected customers should do now

  1. Check official notices. Open Coupang directly through the known app or website and review account messages. Do not use links in unsolicited texts or emails.
  2. Change reused passwords. Change the Coupang password if it was reused, then change that password anywhere else it appeared, especially email, banking, shopping and delivery services.
  3. Enable multifactor authentication. Turn it on for email, financial accounts and other services that support it.
  4. Review account activity. Check orders, saved addresses, account details and payment settings for changes you did not make.
  5. Protect building access. If a building-entry code was stored in delivery information, change it where the building permits.
  6. Expect targeted phishing. Be suspicious of messages about deliveries, refunds, account suspension or compensation vouchers. Never provide passwords, one-time codes, card details or remote-access permission.
  7. Monitor financial accounts. Review bank and card statements even though Coupang said payment-card information was not compromised.
  8. Preserve evidence. Save suspicious messages, headers, screenshots, unauthorized-order details and records of harassment or fraud.
  9. Use official Korean channels. Customers in Korea can consult Coupang’s notices and applicable PIPC or dispute-resolution channels for notifications and remedies.

These steps reduce risk; they do not prove that a particular customer experienced identity theft or financial loss. Customers outside South Korea should recognize that the official investigation primarily concerns Coupang’s Korean operations and Korean privacy procedures.

What remains unresolved?

  • Whether every affected user and non-member data subject received adequate notice.
  • The final legal status of PIPC’s sanctions, including any appeal or court challenge.
  • The outcome and eligibility rules for collective dispute resolution.
  • Whether additional compensation or private litigation will follow.
  • Whether authorities will publish a definitive reconciliation of account, record, access-event and third-party counts.
  • The full operational terms and continuing status of Coupang’s voucher program.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Money Desk

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.