Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
The Coupang cyber attack stands out not because of ransomware or dramatic system outages, but because of how quietly and persistently it unfolded. Beginning in late June 2025, an unauthorised actor maintained sustained access to Coupang’s internal systems for almost five months before the intrusion was finally uncovered in mid-November. During that time, the attacker was able to move freely across internal environments and access large-scale customer databases. Ultimately, the attack exposed data linked to approximately 33.7 million users. The duration, scale, and delayed detection placed this incident among the most serious cybersecurity breaches in South Korea’s history.
Our Coupang Cyber Attack Timeline breaks the incident down step by step. We show you how the access began, why it went undetected for months, and what finally forced containment. Download the timeline to gain a fast, executive-friendly understanding of how insider access, delayed credential revocation, and weak monitoring can escalate into a crisis of national significance and what organisations must prioritise now to prevent similar failures.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.