Summary
Coupang, Inc. (CPNG) has disclosed a material cybersecurity incident impacting its Korean subsidiary, Coupang Corp. The company became aware of unauthorized access to customer accounts on November 18, 2025, attributed to a former employee. The breach potentially exposed the names, phone numbers, delivery addresses, and email addresses of up to 33 million customer accounts, along with order histories for a subset of these accounts. Notably, Coupang states that no banking or payment card information, or login credentials were compromised. While Coupang has activated its incident response, disabled unauthorized access, and notified relevant authorities and affected customers, ongoing investigations by external experts and Korean regulators are underway. The company acknowledges the potential for material financial penalties from regulators and the risk of financial losses stemming from remediation efforts, potential loss of revenue, and litigation. Operations have not been materially disrupted, but management's attention and resources may be diverted. A leadership change at the Korean subsidiary, with the former CEO resigning and an interim CEO appointed, is also noted.
Key Highlights
- 1Coupang reports a cybersecurity incident affecting its Korean subsidiary, Coupang Corp., discovered on November 18, 2025.
- 2Up to 33 million customer accounts potentially exposed, including name, phone number, delivery address, and email address.
- 3Order histories for a subset of impacted accounts may have been accessed.
- 4No customer banking, payment card information, or login credentials were compromised.
- 5Investigations by external forensic experts and Korean regulators are ongoing; Coupang is cooperating fully.
- 6Coupang anticipates potential financial penalties from Korean regulators and acknowledges risks of revenue loss, increased expenses, and litigation.
- 7The former CEO of Coupang Corp. resigned on December 10, 2025; an interim CEO has been appointed.