Summary
Coupang, Inc. has filed an 8-K/A to provide crucial updates regarding a previously disclosed cybersecurity incident. The company announced that the perpetrator has been identified and is cooperating with investigators, having surrendered all relevant devices. While approximately 33 million accounts were accessed, the investigation indicates that only limited data from about 3,000 customer accounts was saved, and this data has since been deleted without being shared with any third party. This development suggests a potentially contained breach with mitigated data exfiltration risk for the vast majority of affected customers. However, Coupang is implementing a significant customer compensation program. The company will issue approximately 1.685 trillion Korean Won (roughly $1.2 billion USD) in vouchers to customers notified of the incident in late November 2025. These vouchers, redeemable for future Coupang purchases starting January 15, 2026, will be recognized as a reduction to selling prices and, consequently, revenue. This financial commitment underscores the company's response to the incident and its potential impact on future financial reporting.
Key Highlights
- 1Perpetrator identified and cooperating with investigation; all devices secured.
- 2Limited data saved from only ~3,000 customer accounts; data deleted without third-party sharing.
- 3Approximately 33 million accounts accessed in total.
- 4Customer compensation program to issue ~1.685 trillion KRW (~$1.2 billion USD) in vouchers.
- 5Vouchers will be applied towards future Coupang purchases starting January 15, 2026.
- 6Vouchers will be recognized as reductions to selling price and revenue.
- 7Investigation into the cybersecurity incident remains ongoing.