Skip to content
Managerial negligence, not sophisticated hacking, to blame for Coupang data breach

Managerial negligence, not sophisticated hacking, to blame for Coupang data breach

English.Hani.Co.Kr February 11, 2026

“This was clearly a management issue, not a sophisticated attack,” investigators said of Coupang’s massive personal data leak while announcing the results of their probe on Tuesday.

The joint public-private team looking into the incident pinpointed vulnerabilities in Coupang’s authentication system and insufficient information security management as the cause of the incident.

Despite a former employee generating fake login tokens for nearly a year to gain unauthorized access, Coupang failed to detect or block this activity.

How was Coupang’s system breached?

According to investigators, the attacker who scraped sensitive data from Coupang’s system was a former backend engineer who had designed and developed Coupang’s user authentication system during their tenure at the company.

The former employee exploited a vulnerability in Coupang’s authentication system to access user accounts without going through the normal login procedure, and then illegally scraped customers’ personal information.

Under normal access procedures, users log in by entering their ID and password, then receive an electronic access pass, or token. Coupang’s gateway server verifies the validity of this badge before granting service access. However, the engineer used the signing key from the user authentication system he managed as an employee to generate fake login tokens. This allowed him to access Coupang services without going through the login process.

After leaving the company, the engineer began testing the forged tokens in January 2025. From April 2025, he began using automated web-crawling tools to scrape massive amounts of personal data. Investigators found that a total of 2,313 unique IP addresses were used in this process.

Internal regulations on signing key management were defunct

Coupang remained oblivious to the former employee’s crimes until November 2025, when it received reports of suspected personal information leaks via email. The investigation team pointed to flaws in Coupang’s user authentication system and information security management system as the background to such a large-scale personal information leak on South Korea’s largest e-commerce platform.

Prior to the incident, Coupang addressed some vulnerabilities in its digital access pass-based authentication system through simulating hacking attempts, and these were reported to the chief information security officer. However, the company did not conduct a comprehensive review of the entire user authentication system.

Despite internal regulations that stipulate that signing keys should only be stored in the key management system, investigators found that signing keys were stored not only on the former employee’s laptop but also on those of current Coupang developers. This meant that even after the incident, another attacker could have leaked or abused the signing keys.

Moreover, contrary to internal regulations, there was no system in place to record and manage the issuing history of signing keys. This made it impossible for the company to determine whether they were used for unauthorized purposes.

Investigators explained that access logs were also stored and managed without consistent standards, making it difficult to identify affected users and estimate the scale of the leak.

What penalties will Coupang face?

In addition to the Personal Information Protection Commission’s decision to impose fines on Coupang, the Ministry of Science and ICT will impose fines and request a formal investigation regarding Coupang’s violations of network utilization and information protection laws during its response to the data breach.

Coupang reported the breach to its chief information security officer on Nov. 17, 2025, but only notified the Korea Internet and Security Agency after 9 pm on Nov. 19 — nearly two days after becoming aware of the incident, although it was legally obligated to report within 24 hours. Consequently, a fine of up to 30 million won (US$20,600) is expected to be imposed for its delay in reporting the breach.

Additionally, the ministry stated that Coupang violated a formal order to preserve all records related to the breach. Though the company received the order on Nov. 19, 2025, Coupang failed to adjust its automatic log storage policy for access records. This resulted in the deletion of approximately five months’ worth of web access records starting from July 2024.

This means it is impossible to confirm whether the former employee planned or executed the data breach before resigning from Coupang. Consequently, the probe team has requested a formal investigation regarding this failure to comply with a data preservation order.

Please direct questions or to [ english@hani.co.kr ]