Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Coupang interim CEO apologizes over 33 million users data breach

Coupang’s interim CEO, Harold Rogers, apologized at a parliamentary hearing on December 16 for a data breach that exposed personal information of over 33 million customers in South Korea.

Coupang is a Seoul-based ecommerce firm.

Rogers, who took over after Park Dae-jun resigned following the incident, said the company is working to address concerns from regulators and customers.

The breach was reported in late November.

Coupang founder Kim Bom-suk did not attend the hearing, citing business commitments.

🔗 Source: Yonhap

🧠 Food for thought

Implications, context, and why it matters.

Lax key handling allegedly let a former employee access systems for months

  • Coupang left signing keys (cryptographic keys used to sign and validate authentication tokens) unrotated for 5 to 10 years, so a former employee kept access after leaving 1.
  • Intrusion may have started on June 24, 2025, but detection came on November 18, which left about five months of exposure 2.
  • About 33.7 million users in South Korea saw names, addresses, and phone numbers exposed 2. Some order histories leaked, which raises phishing (fraudulent messages impersonating a trusted party) or identity fraud risk, while payment credentials did not.
  • The case exposes gaps in privileged access management, such as missing automated deprovisioning and weak monitoring of keys or tokens 3.

Regulatory moves may drive identity security upgrades across Korea

  • president Lee Jae Myung backed fines based on a company’s highest annual sales over the past three years, and PIPC chair Song Kyung-hee said penalties could reach 10% in repeated, grave cases 4.
  • Bloomberg estimated Coupang’s exposure at up to 1.2 trillion won, or about US$814 million, based on analysis of the case 1.
  • Vendors in identity and access management see near-term demand for automated deprovisioning, privileged credential lifecycle controls, plus real-time login/token anomaly monitoring 3.
  • PIPC ordered Coupang to change its public notice from “exposure” to “breach” and opened a joint probe with the National Police Agency, Korea Internet & Security Agency (KISA), plus other authorities 2.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.