[비즈한국] One week after a massive personal data breach, Coupang has issued a revised notice following government instructions. The notice to customers includes measures to prevent secondary damage, such as phishing.

In a notice issued on the 7th, Coupang stated, "A personal data breach involving our customers has occurred," adding, "There have been no new leaks; this is to provide guidance on precautions to prevent additional damage such as impersonation or phishing related to the breach previously announced on November 29."
Since late November, Coupang has been notifying customers about a data breach affecting 33.7 million accounts. However, the company issued this new notice as a corrective measure after government agencies, including the Personal Information Protection Commission (PIPC), pointed out the need to re-advise users on how to minimize damage. On the 3rd, the PIPC ordered Coupang to change the term "exposure" to "breach" in its notice and to re-notify customers with a complete list of the leaked information.
Coupang stated, "Immediately upon becoming aware of this breach, we reported it promptly to the relevant authorities," and added, "We are cooperating with the Ministry of Science and ICT, the National Police Agency, the Personal Information Protection Commission, the Korea Internet & Security Agency, and the Financial Supervisory Service for the investigation." They further explained, "The National Police Agency has announced that, to date, no cases of suspected secondary damage using information leaked from Coupang have been discovered through a full-scale investigation."
Previously, Coupang faced criticism for using the term "exposure" rather than "breach" when notifying the subjects of the information after discovering that unauthorized individuals had accessed personal data. During a standing committee meeting at the National Assembly’s Science, ICT, Broadcasting, and Communications Committee on the 2nd, Park Dae-joon, CEO of Coupang’s Korean entity, apologized, saying "We lacked foresight," while claiming there was "no intent" behind using the term "exposure" instead of "breach."
Coupang subsequently clarified that the leaked information included: customer names, email addresses, delivery address books (including names, phone numbers, addresses, and common entrance access codes saved in the address book), and some order information. Coupang emphasized, "Immediately after the incident, we blocked the unauthorized access path and further strengthened our internal monitoring."

Advice on preventing damage was also provided. Coupang urged users, "We never request app installations via phone call or text message. Since scammers may impersonate 'Coupang' through smishing or phishing texts, please never click on links from unknown sources and delete such messages." The company advised users to treat any message not sent through official channels (listed in the mobile/PC app customer center) as potential impersonation or phishing.
Furthermore, they stated, "Please report suspicious calls or text messages to 112 or the Financial Supervisory Service," and recommended using the "Financial Transaction Safe Block Service," while also verifying that text messages are indeed from the official Coupang customer center. It was further emphasized that Coupang delivery drivers do not directly call or text customers unless there are exceptional circumstances, such as difficulties entering the delivery location or missing items for collection. Those who have saved common entrance access codes in their Coupang delivery address book are encouraged to change them.
Coupang reiterated that there has been no secondary damage related to sensitive data, as payment information such as credit card or account numbers, login credentials, and personal customs clearance codes were not leaked. The company explained that while they have checked multiple times, no such leaks have been identified. Regarding common entrance passwords, while they were included in the leaked data, the company maintains that there have been no reported cases of them being misused.
Coupang stated, "Immediately after the incident, we blocked the unauthorized access path and strengthened our internal monitoring," adding, "All Coupang employees will do their utmost to quickly resolve any inconvenience and concern caused to our customers."