주메뉴바로가기본문바로가기
비즈한국 비즈한국

Coupang’s "33.7 Million Personal Records Leaked": A Hurried Apology, But Is It Enough?

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] After the leak of 33.7 million members' personal records was revealed on November 29, Coupang issued an apology letter in the name of its CEO on the afternoon of the 30th, just one day later. It appears the company scrambled to respond after the public backlash following the revelation of the leak the previous day became too significant to ignore.

On Saturday, the 29th, past 5 p.m., Coupang released an official press statement confirming that the names, email addresses, delivery address books, and some order information for approximately 33.7 million member accounts had been exposed without authorization.

Coupang stated that it first became aware of the personal information exposure on November 18. At that time, it claimed it had identified the exposure of 4,500 accounts and immediately reported the incident to relevant authorities (the National Police Agency, the Korea Internet & Security Agency, and the Personal Information Protection Commission). In a statement released on the 20th, the company claimed that "the delivery information of approximately 4,500 people was exposed due to unauthorized access" and emphasized that there were no signs of external hacking. It stated that the perpetrator is believed to have accessed the personal information without authorization via overseas servers starting from June 24, 2025.

A view of Coupang's headquarters located in Songpa-gu, Seoul. The government is investigating the leak of 33.7 million Coupang member accounts. Photo = Reporter Park Jung-hoon
A view of Coupang's headquarters located in Songpa-gu, Seoul. The government is investigating the leak of 33.7 million Coupang member accounts. Photo = Reporter Park Jung-hoon

Coupang also sent text messages to the affected members on the 29th to notify them. However, members reacted coldly, as they had been unaware of the breach for nearly five months, and the company only notified them nearly two weeks after the initial discovery. Furthermore, the text message claiming that "payment information, credit card numbers, and login information were not exposed, so there is no need for customers to take account-related measures" was met with criticism. Critics argued that even though the personal information of virtually all members was leaked, the company’s awareness of the reality and its response were complacent.

In response, Coupang issued an apology on the afternoon of the 30th at approximately 3:50 p.m., titled "We sincerely apologize for causing concern and worry to the public," signed by CEO Park Dae-joon, as the company attempted to mitigate the situation.

The swift government response also appears to have been a factor. The Ministry of Science and ICT (MSIT), the competent ministry, launched a joint public-private investigation team the day after the incident was reported on the 29th. An emergency countermeasure meeting involving relevant agencies was also held, chaired by Deputy Prime Minister and Minister of Science and ICT Bae Gyeong-hoon. The meeting was attended by the Minister of the Office for Government Policy Coordination, the Chairperson of the Personal Information Protection Commission, the Third Deputy Director of the National Intelligence Service, and the acting Commissioner General of the Korean National Police Agency.

According to the MSIT, the government has been conducting an on-site investigation since receiving the incident report from Coupang on November 19 and the personal information leak report on November 20. During the investigation, it was confirmed that the attacker exploited an authentication vulnerability in Coupang's server to leak customer names, emails, delivery phone numbers, and addresses of over 30 million customer accounts without normal login procedures. The Personal Information Protection Commission is also intensely investigating whether Coupang violated safety obligation requirements related to personal information protection (such as access control, management of access rights, and encryption).

According to multiple media reports, the perpetrator behind the leak is known to be a Chinese national who formerly worked at Coupang. The Seoul Metropolitan Police Agency's Cyber Investigation Division received a criminal complaint from Coupang on the 25th and has launched an investigation.

Meanwhile, extreme caution is advised, as the leaked personal information is expected to be used for smishing and voice phishing attacks. If you receive a text message containing keywords such as "damage compensation," "damage inquiry," or "refund," do not click on the URL in the text; instead, report it as spam, block it, or report it to the Voice Phishing Integrated Reporting and Response Center. Smishing and phishing sites can be identified and reported by using the "Smishing Verification Service" within the "BohoNara" (Protection Nation) KakaoTalk channel.

For related inquiries, you can call the Korea Internet & Security Agency's Internet Cyber Security Center at 118 (no area code needed).

This article was automatically translated by AI. There may be errors compared to the original Korean article.
김남희 기자

문화예술 분야와 콘텐츠 관리를 담당합니다.

namhee@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지