Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Coupang staff obstructed data breach probe, ministry says

South Korea’s Ministry of Science and ICT reported that Coupang staff obstructed an investigation by deleting sensitive information and failing to preserve access logs, violating orders.

The breach exposed personal data of nearly 34 million customers, including names, phone numbers, addresses, and building access codes, contradicting the company’s earlier claims of fewer affected users.

The investigation identified a former Coupang engineer as the intruder, who accessed 25.6 terabytes of data between April and November 2025 and tested the vulnerability as early as January 2024.

The intruder claimed customers in Japan and Taiwan were also impacted.

The ministry said the breach involved a vulnerability putting billions of user data items at risk.

Multiple Korean agencies, including the Personal Information Protection Commission and the National Police Agency, are conducting further investigations.

Coupang criticized the probe as unfair.

🔗 Source: Bloomberg

🧠 Food for thought

Implications, context, and why it matters.

The breach came from weak credential and key handling, not an advanced hack

  • Investigators tied the incident to gaps in basic security controls and internal credential handling, not an elaborate attack method 1.
  • A former Coupang engineer used an authentication signing key taken during employment to create an electronic access badge, meaning access tokens, and skip normal login steps 1.
  • Signing keys linked to former staff stayed active without revocation or rotation, while the system failed to properly check forged credentials, so unusual access continued for months 1.
  • Coupang first said about 3,000 accounts were affected, yet a joint probe later found leaked names and email addresses for 33.67 million users, plus phone numbers, addresses, and building access codes, separate from an additional 165,000-account leak Coupang later reported 2.

The breach has turned into a Korea-U.S. political and trade dispute

  • The inquiry moved beyond a local regulatory matter and became a point of tension in U.S.-South Korea relations 3.
  • Greenoaks Capital Partners and Altimeter Capital Management, both major U.S. investors in Coupang, petitioned the U.S. Trade Representative, the U.S. agency that handles trade policy and disputes, and argued the probe is discriminatory while seeking remedies that include tariffs on Korean exports 3.
  • The issue led to talks between U.S. vice president JD Vance and South Korea’s prime minister Kim Min-seok, and both governments agreed to set up a hotline to manage it 3.
  • The case now shapes debate over how South Korea regulates multinational or foreign-linked consumer internet platforms, with some commentary warning of a chill in foreign investor sentiment if South Korea is seen as an unpredictable market 4.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.