[비즈한국] 33.7 million pieces of personal information were "exposed" at Coupang. The exposed data includes names, phone numbers, addresses, emails, shipping information, and order history. In terms of sheer scale, it is the largest incident ever experienced by a domestic e-commerce company, yet Coupang is managing the situation with a calm and measured demeanor.
The scale of the "exposure," which was initially reported as just 4,500 cases, grew to 33.7 million during subsequent investigations. From a corporate perspective, however, this appears to be a process of disclosing information in stages only after it has been definitively verified. It is the most basic and verified method used by responsible companies during a crisis.
It is in the same vein that Coupang insisted on using the term "exposure" rather than "leakage" in the early stages of the incident. In a situation where technical analysis is not yet complete, a single word can shift the scope of liability. This choice of language is not merely a matter of expression, but a legal strategy that influences future lawsuits, fines, and the intensity of regulations. Considering this, one can see the seasoned expertise of Coupang’s legal team, which has experienced various legal disputes ranging from the deaths of night-shift logistics workers to "blacklist" allegations and controversies over abuse of power against suppliers.
Furthermore, the exclusive report by some media outlets suggesting the incident was the work of a former Chinese employee also implies that the external communication organization is responding rapidly. Considering the recent rise in anti-Chinese sentiment in domestic public opinion, this has the effect of naturally shifting the focus of the incident from internal management issues to external attacks—specifically, allegations of hacking by a certain country.
However, Coupang cannot avoid admitting fault entirely. A certain level of accountability must be expressed, and an apology statement under the CEO’s name is the minimum necessary measure. They have already placed it in the most visible spot at the top of their homepage, right next to their Christmas big sale advertisement.

Although the word "exposure" faced much criticism and should have been replaced with "unauthorized access," the statement includes all the necessary phrases to reassure consumers. These include claims that the company considers customer data protection a top priority, that the leaked information did not include account details, payment info, or credit card numbers, and that there are currently no issues with the security system. These are phrases that have appeared repeatedly whenever a major personal information incident occurs in Korea, effectively becoming the "standard" for apology statements.
What is the remaining response strategy for Coupang? In truth, the answer is already decided. They only need to respond to every subsequent question like this:
“The specific facts are currently under investigation, so it is difficult to disclose them.”
This single sentence is a universal phrase that can wrap up various questions at once. It is valid for questions regarding damage relief or compensation plans, and it also applies to debates over liability, such as whether it was an insider job or an external hack. It is standard corporate practice not to hastily confirm a specific cause or assign liability. Naturally, investigations take time. And this "time" itself plays an important role in cooling down the situation.
Consumers are busy, and it is difficult for them to maintain anger for long. This is not just a Coupang problem, but a recurring pattern in most personal information breach incidents. Initially, public criticism is fierce, but after a few days, it gets buried under other issues. Our dynamic society never stops creating new events, and people's attention naturally shifts in those directions.
By the time other big and small events steal the public's attention, they will announce a reasonable compensation plan. Considering the compensation scale of the three major mobile carriers, a package consisting of one month of free Wow membership and a 10,000 won discount coupon for purchases over 30,000 won seems appropriate. Such benefits result in high satisfaction because consumers can use them immediately, and it also helps the company recover temporarily declined sales.
Once public opinion and media interest have completely cooled, the final investigation results will be announced, and once the compensation is paid out, the outward appearance of the incident will be effectively resolved. Whatever the conclusion of the investigation, consumers' interest will have already waned. Coupang’s service will continue to operate just as it did before, as if nothing happened.
In the end, while this incident is a very large-scale security failure on record, it is highly likely that it will not lead to significant changes in the actual handling process. Korea's personal information protection environment has already developed a certain "settlement pattern" through numerous leaks, and major platforms have continued to respond within that framework. Thus, corporate vigilance and security investment costs are poised to rise, only to stagnate as they were, eventually leading to yet another security incident.
So, this Coupang personal information "exposure" incident is also no big deal. Just as it always is.