8-KOther Events

Coupang, Inc. 8-K Report, Cybersecurity Incident (Dec 16, 2025)

Filed December 16, 2025For Securities:CPNG

Summary

Coupang, Inc. (CPNG) has disclosed a material cybersecurity incident impacting its Korean subsidiary, Coupang Corp. The company became aware of unauthorized access to customer accounts on November 18, 2025, attributed to a former employee. The breach potentially exposed the names, phone numbers, delivery addresses, and email addresses of up to 33 million customer accounts, along with order histories for a subset of these accounts. Notably, Coupang states that no banking or payment card information, or login credentials were compromised. While Coupang has activated its incident response, disabled unauthorized access, and notified relevant authorities and affected customers, ongoing investigations by external experts and Korean regulators are underway. The company acknowledges the potential for material financial penalties from regulators and the risk of financial losses stemming from remediation efforts, potential loss of revenue, and litigation. Operations have not been materially disrupted, but management's attention and resources may be diverted. A leadership change at the Korean subsidiary, with the former CEO resigning and an interim CEO appointed, is also noted.

Key Highlights

  • 1Coupang reports a cybersecurity incident affecting its Korean subsidiary, Coupang Corp., discovered on November 18, 2025.
  • 2Up to 33 million customer accounts potentially exposed, including name, phone number, delivery address, and email address.
  • 3Order histories for a subset of impacted accounts may have been accessed.
  • 4No customer banking, payment card information, or login credentials were compromised.
  • 5Investigations by external forensic experts and Korean regulators are ongoing; Coupang is cooperating fully.
  • 6Coupang anticipates potential financial penalties from Korean regulators and acknowledges risks of revenue loss, increased expenses, and litigation.
  • 7The former CEO of Coupang Corp. resigned on December 10, 2025; an interim CEO has been appointed.

Frequently Asked Questions

The compromised data includes the name, phone number, delivery address, and email address for up to 33 million customer accounts. Additionally, order histories for a subset of these accounts may have been accessed. Coupang explicitly states that no customer banking information, payment card information, or login credentials were obtained.

Coupang has activated its incident response plan, secured systems, reported the incident to authorities, and is notifying affected customers. External forensic experts are assisting with the investigation, and Coupang is cooperating with Korean regulatory and law enforcement agencies. The company anticipates potential financial penalties from regulators and faces risks of financial losses from remediation expenses, potential loss of revenue, and litigation.

Coupang states that its operations have not been materially disrupted. However, the incident has led to a diversion of management's attention and resources. The former chief executive officer of its Korean subsidiary, Coupang Corp., resigned on December 10, 2025, with an interim CEO appointed to lead the subsidiary.

Coupang acknowledges that one or more Korean regulators will potentially impose financial penalties. However, at the time of filing, the company cannot reasonably estimate the amount or range of such losses.