주메뉴바로가기본문바로가기
비즈한국 비즈한국

Sellers report "sharp drop in sales" after data leak... Is Coupang’s 'loyal customer' base crumbling?

This article was automatically translated by AI. There may be errors compared to the original Korean article.  Read original in Korean →

[비즈한국] As a massive customer data leak incident unfolds, analysts suggest that Coupang is facing the most serious crisis since its founding. Posts recruiting participants for class-action lawsuits are appearing one after another on online communities, and the movement to 'delete Coupang accounts' is spreading rapidly. With sellers even claiming that their sales have dropped due to customer attrition, a sense of anxiety is spreading across the entire platform.

A massive data breach involving over 30 million records has occurred at Coupang, the number one e-commerce player in the domestic market. Photo = Reporter Park Jung-hoon
A massive data breach involving over 30 million records has occurred at Coupang, the number one e-commerce player in the domestic market. Photo = Reporter Park Jung-hoon

"Bound to happen": Controversy over holes in Coupang’s security management

On November 29, Coupang officially announced, "It has been confirmed that approximately 33.7 million customer accounts were accessed without authorization." The leaked information reportedly includes names, emails, phone numbers, delivery addresses, and order history. Coupang explained, "Login credentials such as passwords and card/payment information were not exposed."

The scale of this leak is the largest since the 2011 Cyworld and Nate hacking incidents, which compromised the personal information of about 35 million people. According to IGAWorks Mobile Index, Coupang’s monthly active users (MAU) reached 34.38 million as of October; considering this, it is effectively as if the information of almost every user has been exposed.

In particular, as it was revealed that this incident stemmed from a mass data leak by a Chinese national developer who worked at Coupang, questions regarding Coupang's overall internal control system are mounting. Since the breach was caused by unauthorized access by an insider rather than an external hack, critics are pointing out that the security structure itself may be fundamentally flawed.

The industry has raised issues regarding Coupang’s security risks multiple times in the past. Allegations that former employees continued to access Coupang’s systems or utilized internal information for their own private businesses have consistently surfaced.

One seller shared, "Among advertising and marketing agencies, there are some that know internal details about sellers all too well. When I asked how they knew, they replied, 'I'm from Coupang, so I can check internal information in real time.'" The seller added, "Does it make sense that former personnel can still access internal systems like this? Yet, Coupang didn't seem to view this as a major problem."

Experts also point out that structural defects have been exposed in Coupang’s overall security management system. Yeom Heung-ryeol, an honorary professor of Information Security at Soonchunhyang University, said, "The basic principle is to immediately revoke the access rights of former employees (insiders). It is highly questionable that such a security management system did not function properly and that no immediate measures were taken after the data breach." He added, "Using internal information is clearly illegal, but given the nature of the era where personal data is money, former employees are inevitably exposed to various temptations. Managing departing employees is the foundation of security, and the fact that this wasn't strictly followed is likely where the incident began."

This incident is known to have been caused by a Chinese national developer who worked at Coupang leaking customer information, not by an external hack. Photo = Reporter Park Jung-hoon
This incident is known to have been caused by a Chinese national developer who worked at Coupang leaking customer information, not by an external hack. Photo = Reporter Park Jung-hoon

Class actions and account deletions: Sellers anxious over falling sales

Industry experts predict this incident will lead directly to a decline in consumer trust in Coupang. Analysts believe that because it took five months to identify the situation—even though the data leak had been occurring since June—consumer disappointment and distrust have deepened. Consumers preparing for class-action lawsuits against Coupang are increasing rapidly. Over a dozen online communities related to the lawsuits have already been established, and some exceeded 100,000 members in less than a week. On the 1st, some users filed a damage suit at the Seoul Central District Court, claiming 200,000 won in consolation money per person from Coupang.

Coupang has faced various social criticisms in the past, such as worker fatalities and controversies over commission fees. Yet, the reason for its continued growth was its solid 'loyal customer base.' Policies prioritizing consumer convenience, such as Rocket Delivery and free returns, acted as a powerful competitive advantage, ensuring almost no customer churn despite various controversies.

However, many point out that this personal data breach is different in nature from previous controversies. The prediction is that as the trust foundation for the platform wavers, the psychological barrier for consumers will rise. A movement to delete Coupang accounts is spreading, centered on online communities and social media. Meanwhile, industry attention is focused on Coupang’s follow-up measures, but it is reported that discussions on compensation packages have not yet begun in earnest within the company.

Park Dae-joon, CEO of Coupang, attends a meeting of the National Assembly's Science, ICT, Broadcasting, and Communications Committee on the 2nd to answer questions regarding the Coupang security breach. Photo = Reporter Park Eun-sook
Park Dae-joon, CEO of Coupang, attends a meeting of the National Assembly's Science, ICT, Broadcasting, and Communications Committee on the 2nd to answer questions regarding the Coupang security breach. Photo = Reporter Park Eun-sook

The ones feeling most anxious as they watch the situation unfold are none other than the sellers on Coupang. This is because if customer attrition accelerates, sellers are the first to be hit. One seller said, "Perhaps due to the data leak, sales have dropped by nearly 70% compared to last week. I'm worried because the atmosphere seems to be taking a more serious turn than expected. There is talk among sellers about lowering our reliance on the Coupang platform and securing alternative sales channels like Naver Smart Store."

Experts analyze that if customer and seller churn occur simultaneously, the crisis facing Coupang could deepen significantly. They argue that once consumer trust is shaken, order volumes drop; if sales anxiety rises, sellers move to other platforms, causing a 'vicious cycle' that weakens the ecosystem itself. Lee Eun-hee, a professor of Consumer Science at Inha University, pointed out, "It is known that about 600,000 people left after the SK Telecom hacking. A certain level of membership attrition is inevitable in this Coupang incident as well. The attitude of companies focusing only on outward growth while being negligent toward information protection and consumer safety is fueling consumer backlash."

The government is also viewing this massive data leak incident with gravity. On the 2nd, President Yoon Suk Yeol stated at a cabinet meeting held at the Yongsan Presidential Office, "We will hold Coupang strictly accountable for the customer data leak." The President emphasized, "We must use this opportunity to completely change the wrong practices and perceptions that have neglected personal information protection. Related ministries should refer to overseas cases to strengthen fines and make punitive damage systems realistic, taking practical and effective measures."

Yeom Heung-ryeol, an honorary professor of Information Security at Soonchunhyang University, emphasized, "In Korea, the basic principle is 'autonomous security,' where companies build and operate their own security systems, so the primary responsibility for personal information leakage accidents lies with the company. It is necessary to establish an effective inspection and supervision system within a range that does not excessively infringe upon management activities."

This article was automatically translated by AI. There may be errors compared to the original Korean article.
박해나 기자

유통 산업과 기업 이슈를 취재합니다. 놓치고 있는 이야기가 있다면 들려주세요.

phn0905@bizhankook.com
저작권자 ⓒ 비즈한국 무단전재 및 재배포 금지