Skip to content
Coupang disputes findings of joint probe, claims only 2,609 accounts with lobby codes leaked

Coupang disputes findings of joint probe, claims only 2,609 accounts with lobby codes leaked

Hani.Co.Kr February 12, 2026

Coupang, Korea’s leading e-commerce platform, is disputing the results of a joint public-private investigation into its recent data breach that affected more than 30 million users. The company claims that the investigation team failed to differentiate the number of data queries made and the actual number of accounts that had been accessed. Coupang issued a statement on Tuesday, emphasizing, “There is no evidence of any secondary harm from the Coupang data incident according to the latest analysis from independent security company CNS.”

According to findings announced the same day by the Ministry of Science and ICT from a civilian-government investigation team probe into the data leak at Coupang, the breach by a former employee of the company affected data for 33.67 million users, with around 148 million views of delivery addresses and other personal details.

This included 50,474 views of the company’s delivery address list editing page, which included access codes for shared lobbies.

In its response, Coupang claimed that the former employee had “accessed 2,609 accounts that had building lobby access codes,” adding that it had shared this information last year with investigators and the Personal Information Protection Commission (PIPC). At the same time, it insisted that the joint investigation team’s announcement the lobby access code queries numbering around 50,000 “omits the analysis confirming that those queries accessed 2,609 accounts with building lobby access codes.”

Coupang’s response also stated that no secondary harm or related dark web activities had been observed to date.

Coupang receives weekly updates from multiple independent internet security companies who continuously monitor dark web, deep web, Telegram, and Chinese messaging platforms,” it explained.

The company also expressed disgruntlement over the police investigation.

On Dec. 5 of last year, the Korean National Police Agency’s National Office of Investigation announced that it had identified “no suspected cases of secondary harm involving the exploitation of the types of information leaked from Coupang.” According to Coupang, the agency subsequently changed its position, announcing on Dec. 15 — ahead of a National Assembly hearing — that it was “difficult to conclude [at that stage] whether secondary harm has occurred or not.”

The Coupang response went on to stress, “In the nearly two months since that statement, the police have also not provided any confirmed cases of secondary harm.”

The company further said it would “continue to cooperate fully with the government’s investigation [and] take all necessary steps to prevent further harm.”

“We look forward to the time when all the facts come to light, because the Korean people deserve to know the full truth,” the response concluded.

Please direct questions or to [ english@hani.co.kr ]

Extracted Entities

Attack Types (1)

Companies (1)

Countries (1)

Domains (1)