[비즈한국] As a massive customer data leak incident unfolds, analysts suggest that Coupang is facing the most serious crisis since its founding. Posts recruiting participants for class-action lawsuits are appearing one after another on online communities, and the movement to 'delete Coupang accounts' is spreading rapidly. With sellers even claiming that their sales have dropped due to customer attrition, a sense of anxiety is spreading across the entire platform.

"Bound to happen": Controversy over holes in Coupang’s security management
On November 29, Coupang officially announced, "It has been confirmed that approximately 33.7 million customer accounts were accessed without authorization." The leaked information reportedly includes names, emails, phone numbers, delivery addresses, and order history. Coupang explained, "Login credentials such as passwords and card/payment information were not exposed."
The scale of this leak is the largest since the 2011 Cyworld and Nate hacking incidents, which compromised the personal information of about 35 million people. According to IGAWorks Mobile Index, Coupang’s monthly active users (MAU) reached 34.38 million as of October; considering this, it is effectively as if the information of almost every user has been exposed.
In particular, as it was revealed that this incident stemmed from a mass data leak by a Chinese national developer who worked at Coupang, questions regarding Coupang's overall internal control system are mounting. Since the breach was caused by unauthorized access by an insider rather than an external hack, critics are pointing out that the security structure itself may be fundamentally flawed.
The industry has raised issues regarding Coupang’s security risks multiple times in the past. Allegations that former employees continued to access Coupang’s systems or utilized internal information for their own private businesses have consistently surfaced.
One seller shared, "Among advertising and marketing agencies, there are some that know internal details about sellers all too well. When I asked how they knew, they replied, 'I'm from Coupang, so I can check internal information in real time.'" The seller added, "Does it make sense that former personnel can still access internal systems like this? Yet, Coupang didn't seem to view this as a major problem."
Experts also point out that structural defects have been exposed in Coupang’s overall security management system. Yeom Heung-ryeol, an honorary professor of Information Security at Soonchunhyang University, said, "The basic principle is to immediately revoke the access rights of former employees (insiders). It is highly questionable that such a security management system did not function properly and that no immediate measures were taken after the data breach." He added, "Using internal information is clearly illegal, but given the nature of the era where personal data is money, former employees are inevitably exposed to various temptations. Managing departing employees is the foundation of security, and the fact that this wasn't strictly followed is likely where the incident began."

Class actions and account deletions: Sellers anxious over falling sales
Industry experts predict this incident will lead directly to a decline in consumer trust in Coupang. Analysts believe that because it took five months to identify the situation—even though the data leak had been occurring since June—consumer disappointment and distrust have deepened. Consumers preparing for class-action lawsuits against Coupang are increasing rapidly. Over a dozen online communities related to the lawsuits have already been established, and some exceeded 100,000 members in less than a week. On the 1st, some users filed a damage suit at the Seoul Central District Court, claiming 200,000 won in consolation money per person from Coupang.
Coupang has faced various social criticisms in the past, such as worker fatalities and controversies over commission fees. Yet, the reason for its continued growth was its solid 'loyal customer base.' Policies prioritizing consumer convenience, such as Rocket Delivery and free returns, acted as a powerful competitive advantage, ensuring almost no customer churn despite various controversies.
However, many point out that this personal data breach is different in nature from previous controversies. The prediction is that as the trust foundation for the platform wavers, the psychological barrier for consumers will rise. A movement to delete Coupang accounts is spreading, centered on online communities and social media. Meanwhile, industry attention is focused on Coupang’s follow-up measures, but it is reported that discussions on compensation packages have not yet begun in earnest within the company.

The ones feeling most anxious as they watch the situation unfold are none other than the sellers on Coupang. This is because if customer attrition accelerates, sellers are the first to be hit. One seller said, "Perhaps due to the data leak, sales have dropped by nearly 70% compared to last week. I'm worried because the atmosphere seems to be taking a more serious turn than expected. There is talk among sellers about lowering our reliance on the Coupang platform and securing alternative sales channels like Naver Smart Store."
Experts analyze that if customer and seller churn occur simultaneously, the crisis facing Coupang could deepen significantly. They argue that once consumer trust is shaken, order volumes drop; if sales anxiety rises, sellers move to other platforms, causing a 'vicious cycle' that weakens the ecosystem itself. Lee Eun-hee, a professor of Consumer Science at Inha University, pointed out, "It is known that about 600,000 people left after the SK Telecom hacking. A certain level of membership attrition is inevitable in this Coupang incident as well. The attitude of companies focusing only on outward growth while being negligent toward information protection and consumer safety is fueling consumer backlash."
The government is also viewing this massive data leak incident with gravity. On the 2nd, President Yoon Suk Yeol stated at a cabinet meeting held at the Yongsan Presidential Office, "We will hold Coupang strictly accountable for the customer data leak." The President emphasized, "We must use this opportunity to completely change the wrong practices and perceptions that have neglected personal information protection. Related ministries should refer to overseas cases to strengthen fines and make punitive damage systems realistic, taking practical and effective measures."
Yeom Heung-ryeol, an honorary professor of Information Security at Soonchunhyang University, emphasized, "In Korea, the basic principle is 'autonomous security,' where companies build and operate their own security systems, so the primary responsibility for personal information leakage accidents lies with the company. It is necessary to establish an effective inspection and supervision system within a range that does not excessively infringe upon management activities."