Skip to content
Coupang Data Breach Exposes Personal Information of 33.7 Million Users

Coupang Data Breach Exposes Personal Information of 33.7 Million Users

Dongascience November 30, 2025

With the confirmation that the personal information of approximately 33.7 million customers of Coupang, a major South Korean online shopping mall, has been leaked, the government is forming a public-private joint investigation team to analyze the cause of the incident. A public warning has been issued for potential smishing·phishing attacks aimed at stealing personal and financial data.

The Ministry of Science and ICT (MSIT) and the Personal Information Protection Commission (PIPC) announced their response plans on the 29th, including an investigation, as the scale of the Coupang data breach expanded significantly. To prevent secondary damage, such as smishing attacks exploiting the leaked information, a public security notice was issued through the official website Boho.or.kr.

Coupang initially reported on the 19th that information such as customer names, emails, and addresses from 4,536 accounts had been leaked. However, during the investigation, it was determined that data from 33.7 million accounts had been compromised.

Considering the severity of the incident, including the massive scale of the leak and the risk of further harm to the public, the MSIT plans to form a public-private joint investigation team on the 30th to analyze the cause of the breach and develop measures to prevent a recurrence.

The PIPC received data breach reports from Coupang on two occasions, November 20th and November 29th, and has been investigating the matter since the 21st. As the leaked data includes the information and addresses of a large number of people, the commission plans to conduct a swift investigation and impose strict penalties if Coupang is found to have violated its safety obligations under the Personal Information Protection Act.

Coupang stated, "Payment information, credit card numbers, and login credentials were not included in the breach."

Link: Warning advisory for smishing·phishing attacks exploiting e-commerce hacks

boho.or.kr/kr/bbs/view.do?bbsId=B0000133&pageIndex=1&nttId=71910&menuNo=205020

Extracted Entities

Attack Types (2)

Companies (1)

Countries (1)

Domains (2)