🧔♂️ A friendly human may check it before it goes live. More news here
Coupang daily users fall to 14.9 million after data breach
Coupang’s daily active user (DAU) count fell to the 14 million range after the company disclosed a major data breach, according to industry tracker IGAWorks’ MobileIndex, it is the lowest since October 25, 2025.
Coupang’s DAU spiked to a record 18.0 million on December 1, 2025 as users checked their accounts, but numbers have since declined, returning to the mid-15 million range by December 10, 2025 and continuing to fall.
The company confirmed on November 29, 2025 that the personal information of 33.7 million customer accounts had been exposed, a figure much higher than the 4,500 initially reported.
The compromised data included names, phone numbers, email addresses, and delivery addresses.
🔗 Source: Yonhap
🧠 Food for thought
Implications, context, and why it matters.
Authorities suspect a Chinese ex-employee; long-valid authentication keys left active for years enabled access
- Authorities suspect a former Chinese national developer who ran Coupang’s authentication system kept access after leaving by misusing authentication tokens (digital credentials that grant access) plus signature keys (cryptographic keys used to sign and validate requests) that were never revoked 1.
- Those keys stayed valid for up to a decade, which let servers be reached without login checks because they were never rotated (regularly replaced) 1.
- The attacker hit an overseas server on June 24 and stayed hidden until November 18, pulling data for nearly five months before discovery 2.
- This lapse came despite Coupang spending 89 billion won ($60.6 million) on information security in 2025 3.
- The National Assembly committee chair called it a “fundamental internal failure,” then criticized the company for leaving authentication keys active for years 1.
Security vendors can stand out with key rotation and cross-border access audits
- The breach revealed 270 Chinese developers in Coupang’s Shanghai, Beijing, and Shenzhen offices 1. The news sharpened debate on foreign access in Korean digital infrastructure 1.
- Cross-border deals like Gmarket’s partnership with Alibaba (Gmarket is a major Korean online marketplace; Alibaba is a Chinese ecommerce giant) complicate governance and raise exposure risk, with Chinese platforms expanding in Korea 1.
- Emergency audits are underway across e-commerce, with platforms like Gmarket and SSG.com (Shinsegae Group’s online retail platform) tightening internal controls 1.
- Tools that matter include automated key rotation (regularly replacing access keys so old ones stop working) 1. Vendors should add privileged access management for offshore teams (limiting and monitoring powerful admin permissions for staff outside the home country) plus real-time anomaly detection for authentication abuse (systems that automatically flag unusual access behavior) 1.
Recent Coupang developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




