Educational & easy-to consume visual guides to understanding attacks & enhancing resilience
The Coupang cyber attack stands out not because of ransomware or dramatic system outages, but because of how quietly and persistently it unfolded. Beginning in late June 2025, an unauthorised actor maintained sustained access to Coupang’s internal systems for almost five months before the intrusion was finally uncovered in mid-November. During that time, the attacker was able to move freely across internal environments and access large-scale customer databases. Ultimately, the attack exposed data linked to approximately 33.7 million users. The duration, scale, and delayed detection placed this incident among the most serious cybersecurity breaches in South Korea’s history.
Our Coupang Cyber Attack Timeline breaks the incident down step by step. We show you how the access began, why it went undetected for months, and what finally forced containment. Download the timeline to gain a fast, executive-friendly understanding of how insider access, delayed credential revocation, and weak monitoring can escalate into a crisis of national significance and what organisations must prioritise now to prevent similar failures.
Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.
Coupang — South Korea's largest e-commerce company, often called the 'Amazon of South Korea' — suffered a major data breach disclosed in late 2025. An unauthorised actor maintained sustained access to its internal systems from late June 2025, going undetected for almost five months until mid-November. During that time the intruder moved freely across internal environments and queried large customer databases, ultimately exposing data linked to approximately 33.7 million customer accounts. Investigators identified the attacker as a former employee who retained internal access after leaving. The scale, duration and delayed detection made it one of the largest data breaches in South Korea's history.
Coupang's investigation indicated unauthorised access to personal information began on 24 June 2025 and continued, undetected, for nearly five months. Coupang first detected unusual activity affecting around 4,500 accounts on 18 November 2025, and a deeper probe revealed on 29 November 2025 that about 33.7 million accounts were affected. The company made its first public disclosures around 1 December 2025, and the fallout — police raids, a CEO resignation, lawsuits and a compensation programme — ran through December 2025 and into early 2026.
Media reports, company statements and police briefings identified the attacker as a former Coupang employee who retained internal access after leaving the company. Investigators said the individual abused legitimate internal credentials, long-lived authentication tokens and an electronic signature or security key, accessing systems from overseas. The activity was consistent with credential misuse and deliberate database querying rather than malware or automated exploitation. South Korean prosecutors pursued an arrest warrant and began international cooperation to locate the suspect, who was believed to be overseas.
This was an insider-access incident rather than a malware-based hack. The former employee used valid internal credentials and a stolen internal security key, connecting from overseas servers to query customer databases without immediately triggering alarms. Investigators pointed to weaknesses in privileged access management, delayed revocation of credentials after the employee's departure, long-valid authentication keys and insufficient anomaly detection — all of which let the activity continue unnoticed for months.
Coupang said the exposed data included customer names, email addresses, phone numbers, shipping addresses and selected order histories, with some users also affected by the exposure of building entrance codes. The company stressed that passwords, payment card details and other financial credentials were not compromised. Because contact and address data were exposed, customers faced heightened risks of phishing, impersonation and delivery-related fraud.
Approximately 33.7 million customer accounts in South Korea were affected. Coupang initially detected unauthorised access to around 4,500 accounts on 18 November 2025, but a subsequent forensic probe revealed on 29 November that the true scale was about 33.7 million — effectively most of its domestic user base — making it one of South Korea's largest-ever data incidents.
No. Investigators, media outlets and Coupang's own disclosures consistently stated that no ransom demand or extortion attempt was made. The incident was treated as an unauthorised internal data-access case rather than a ransomware attack, and Coupang reported no prolonged service outages — the core problem was that the access persisted for months before detection.
After detecting the breach on 18 November 2025, Coupang immediately notified the National Police Agency, KISA and the Personal Information Protection Commission. It blocked the identified access route, revoked compromised credentials, strengthened logging and monitoring, and retained an independent cybersecurity firm for forensics. It issued public disclosures, sent notices and SMS alerts to affected customers, and cooperated with a criminal investigation that included police raids on its offices. Founder Bom Kim later issued a public apology, and the South Korean CEO resigned over the delayed detection.
Yes. On 29 December 2025, founder Bom Kim announced a customer compensation programme worth about 1.69 trillion won (roughly $1.1-1.2 billion), offering vouchers to affected users. Reporting described it as one of the largest consumer remediation efforts following a data breach in Asia, aimed at rebuilding customer trust.
The fallout was severe. Coupang's South Korean CEO resigned on 10 December 2025, citing responsibility for delayed detection. The company faced a US securities class-action lawsuit alleging it failed to promptly disclose the breach, South Korean regulators signalled potentially heavy fines under the Personal Information Protection Act, and its share price came under pressure, reported as down around 31% over three months. The breach also shifted consumer behaviour in South Korea and sparked a national debate on corporate data protection.
The Coupang breach mattered because of its scale, duration and cause. Around 33.7 million accounts — effectively most of South Korea's online shoppers — were exposed by an insider who retained access for almost five months without detection. It drew direct attention from South Korea's president, triggered emergency regulatory action and a criminal investigation, and showed how insider threats and weak access governance can escalate into an incident of national significance, even without ransomware or system outages.
The Coupang incident is a textbook insider-threat and access-governance failure. The key lessons are that credentials, tokens and security keys must be revoked immediately when employees leave; privileged access needs least-privilege controls and continuous monitoring; long-lived authentication keys are dangerous and should be rotated and time-limited; and strong anomaly detection is essential to catch slow, low-noise data exfiltration before it becomes a mass breach. Prompt disclosure and rehearsed crisis communication also limit legal and reputational damage. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.
We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.
Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.
A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.
Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.