South Korean e-commerce platform Coupang over the weekend said nearly 34 million Korean customersโ personal information had been leaked in a data breach that had been ongoing for more than five months.
The company said it first detected the unauthorized exposure of 4,500 user accounts on November 18, but a subsequent investigation revealed that the breach had actually compromised about 33.7 million customer accounts in South Korea.
The breach affected customersโ names, email addresses, phone numbers, shipping addresses and certain order histories, per Coupang. More sensitive data like payment information, credit card numbers, and login credentials was not compromised and remains secure, the company said.
Coupang said it has reported the incident to the Korea Internet Security Agency (KISA), the Personal Information Protection Commission (PIPC), and the National Police Agency.
One of South Koreaโs biggest e-commerce platforms, Coupang also offers a quick-commerce service called โRocket Deliveryโ in the country, and also operates its marketplace in Japan and Taiwan. A Coupang spokesperson told TechCrunch that the investigation has found no evidence that consumer data from Coupang Taiwan or Rocket Now was affected in the data breach.
โAccording to the investigation so far, it is believed that unauthorized access to personal information began on June 24, 2025, via overseas servers,โ the company said. โCoupang blocked the unauthorized access route, strengthened internal monitoring, and retained experts from a leading independent security firm.โ
Police have reportedly identified at least one suspect, a former Chinese Coupang employee now abroad, after launching an investigation following a November 18 complaint.
Techcrunch event
San Francisco
|
October 13-15, 2026
This is the latest in a string of cybersecurity incidents in South Korea this year. Coupang itself has suffered several data breaches that have exposed customer and delivery driversโ information in previous years. Past incidents included leaks between 2020 and 2021, and most recently in December 2023, when its seller management system compromised the personal information of more than 22,000 customers.


