👩🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔♂️ A friendly human may check it before it goes live. More news here
🧔♂️ A friendly human may check it before it goes live. More news here
Coupang interim CEO apologizes over 33 million users data breach
Coupang’s interim CEO, Harold Rogers, apologized at a parliamentary hearing on December 16 for a data breach that exposed personal information of over 33 million customers in South Korea.
Coupang is a Seoul-based ecommerce firm.
Rogers, who took over after Park Dae-jun resigned following the incident, said the company is working to address concerns from regulators and customers.
The breach was reported in late November.
Coupang founder Kim Bom-suk did not attend the hearing, citing business commitments.
🔗 Source: Yonhap
🧠 Food for thought
Implications, context, and why it matters.
Lax key handling allegedly let a former employee access systems for months
- Coupang left signing keys (cryptographic keys used to sign and validate authentication tokens) unrotated for 5 to 10 years, so a former employee kept access after leaving 1.
- Intrusion may have started on June 24, 2025, but detection came on November 18, which left about five months of exposure 2.
- About 33.7 million users in South Korea saw names, addresses, and phone numbers exposed 2. Some order histories leaked, which raises phishing (fraudulent messages impersonating a trusted party) or identity fraud risk, while payment credentials did not.
- The case exposes gaps in privileged access management, such as missing automated deprovisioning and weak monitoring of keys or tokens 3.
Regulatory moves may drive identity security upgrades across Korea
- president Lee Jae Myung backed fines based on a company’s highest annual sales over the past three years, and PIPC chair Song Kyung-hee said penalties could reach 10% in repeated, grave cases 4.
- Bloomberg estimated Coupang’s exposure at up to 1.2 trillion won, or about US$814 million, based on analysis of the case 1.
- Vendors in identity and access management see near-term demand for automated deprovisioning, privileged credential lifecycle controls, plus real-time login/token anomaly monitoring 3.
- PIPC ordered Coupang to change its public notice from “exposure” to “breach” and opened a joint probe with the National Police Agency, Korea Internet & Security Agency (KISA), plus other authorities 2.
Recent Coupang developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




