Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Coupang updates notice after data breach affecting 33.7 million users

Coupang has updated its notice to describe a recent customer data incident as a “breach” after a government order, with authorities saying there is no evidence of further misuse.

The ecommerce company, which is listed in the US and based in South Korea, said the breach affected 33.7 million users and included names, phone numbers, email addresses, and delivery details.

Coupang reported the breach started via overseas servers in June and said it promptly informed authorities.

The company said that no payment information, login credentials, or customs clearance codes were compromised.

Police have not found any cases of secondary damage resulting from the leaked information.

The revised notice follows a directive from South Korea’s Personal Information Protection Commission, which asked Coupang to clarify the scope and seriousness of the incident.

Coupang has advised customers to avoid suspicious links and report any unusual activity.

🔗 Source: Yonhap

🧠 Food for thought

Implications, context, and why it matters.

Coupang’s breach scale could draw a seven-figure USD penalty based on recent Personal Information Protection Commission (PIPC) precedents

  • Golfzon paid KRW 7.5 billion (USD 5.2 million) in May 2024 for a data breach (South Korea’s largest domestic penalty to date) 1.
  • In January 2025, KakaoPay received a KRW 5.9 billion penalty for cross-border transfer violations (moving personal data outside South Korea) 1.
  • Under the 2023 Personal Information Protection Act (PIPA) amendments, penalties can reach 3% of total revenue, excluding revenue unrelated to the violation 1. Given Coupang’s size and the exposed data set, the company could face steep administrative sanctions beyond reputational harm. The data includes names, phone numbers, and addresses.
  • Data controllers (organizations that decide how personal data is processed) must notify the PIPC when breaches affect 1,000 or more people or result from unauthorized external access 2. The commission asked for clarity on scope, a sign of active oversight.

Smishing (SMS-based phishing) risk in South Korea may spike with 33M+ exposed numbers, and telcos (telecommunications carriers) should tighten defenses

  • Keepnet Labs says smishing made up 39% of mobile threats in 2025, and commercial tools blocked only 25 to 35% of attacks 3.
  • Kaspersky blocked 893 million phishing attempts worldwide in 2024, a 26% increase from 2023 4, and the exposed Coupang data gives attackers what they need to craft convincing SMS fraud that impersonates the company.
  • Korean telecommunications carriers and cybersecurity providers should deploy AI-powered detection tuned to Coupang-themed attacks (Keepnet Labs cites 96.2% detection rates) 3.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.