Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Coupang founder apologizes for data breach as probe continues

Coupang founder Kim Bom-suk has issued his first public apology for a major data breach that exposed the personal information of about 34 million users in South Korea.

Coupang is a leading ecommerce platform based in South Korea.

In a written statement, Kim said he was sorry for the delayed response and lack of communication after the incident.

He explained that he waited to confirm all facts before apologizing, which he now considers a mistake.

Coupang said it traced the breach to a former employee through forensic evidence, recovered the equipment used, and obtained a confession.

South Korean authorities have called Coupang’s findings a “unilateral claim,” and said the official investigation is still ongoing.

🔗 Source: Yonhap

🧠 Food for thought

Implications, context, and why it matters.

Coupang acknowledged a breach affecting about 34 million users in South Korea, and authorities criticized slow, limited communication during an ongoing investigation.

  •  Data on 33.7 million included names plus contact details. That exceeds 24.7 million active users and hints at inactive accounts; Coupang has not disclosed retention policies 1.
  •  Access started in June 2025, yet authorities learned in November, implying gaps in monitoring plus late detection 1.
    – Payment data and passwords stayed safe, but orders plus contact info raise phishing or social engineering risks (scams that trick people into revealing sensitive information or making payments) 2.
  •  SK Telecom’s 2025 breach led to a record $97.2 million fine for unencrypted data and unpatched flaws. Coupang’s case exposes gaps such as insider misuse of credentials plus offboarding failures (not promptly removing access when employees leave or change roles) 32.
  •  Scrutiny from lawmakers and regulators is rising. South Korea is reviewing tougher penalties plus broader measures, and law allows fines up to 3% of revenue 1.
  •  Vendors can expect demand for insider‑threat monitoring (tools that detect risky employee or contractor behavior) plus Data Loss Prevention (DLP) plus managed detection services (outsourced 24/7 threat monitoring and response) to avoid penalties.
  •  Regulators fined SK Telecom after failures in encryption plus patch management plus network segmentation 3. Vendors can pitch monitoring plus zero‑trust architectures (a security model that assumes no implicit trust with continuous verification of users plus devices).

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.