The encyclopedia · Software & IT · Operational decision · 2025
Coupang's 2025 breach: 34M accounts exposed by a former employee's data key
In 2025, a former Coupang employee stole a data key and accessed 33.7M accounts — nearly all Korean adults. Korea imposed its largest ever data fine of $409M.
Coupang Inc. · 2025-11
What happened
In December 2025, South Korea's largest e-commerce company Coupang disclosed that a former employee had stolen an internal data key and accessed the personal information of 33.7 million customer accounts — nearly the entire adult population of the country. The breach had been ongoing since June 2025 before it was detected, and between 2,600 and 3,000 accounts had their data actually extracted.
The response was swift and severe. Korea's Personal Information Protection Commission fined Coupang a record 560 billion won (~$409 million), the largest data-protection penalty in the country's history. The government launched a coordinated whole-of-government investigation including police raids on the company's Seoul headquarters, a special tax audit, and parliamentary summons for executives. Coupang committed 1.69 trillion won (~$1.18 billion) to a customer compensation fund.
CEO Park Dae-jun resigned in December 2025. The case became a national scandal because Coupang held data on nearly every Korean adult — its dominance in e-commerce had turned the company into a single point of failure for national personal data security. The breach also created diplomatic friction when U.S. officials warned against what they saw as punitive treatment of an American-listed Korean company.
Why it happened
- A former employee retained or recreated access to an internal data key after leaving the company — the access control system failed to revoke credentials on termination.
- Coupang held personal data on 33.7 million people in a country of 51 million; its dominance meant a single breach exposed nearly the entire adult population.
- The breach ran from June to November 2025 before detection, revealing weak monitoring and anomaly detection on the company's internal data access.
- The scale of the backlash — police raids, parliamentary summons, diplomatic tensions — reflected how deeply a data breach at a near-monopoly can disrupt a country.
The lesson
When a company holds data on an entire population, credential management is national security. A single unrevoked key cascades to the CEO, parliament, and beyond.
Sources
- Coupang data breach — Wikipedia
- Coupang boss quits after data breach exposes 34 million customers — BBC
spotted an error? The club wants to know.
More like this
eBay's 2014 breach exposed 145M users — and the company waited three months to tell them
Terra's 'stablecoin' UST lost its peg — and $40B in crypto value vanished in a week
Samsung shipped the Galaxy Fold to reviewers — and the screens broke in their hands
Somewhere, someone solved the problem this company failed at. 2nd Opinion →

Comments · 0
Sign in to join the comments.