Coupang data breach affecting virtually every user draws apology from CEO

이준혁 2025. 11. 30. 17:21
자동요약 기사 제목과 주요 문장을 기반으로 자동요약한 결과입니다.
전체 맥락을 이해하기 위해서는 본문 보기를 권장합니다.

The vice prime minister added that the government "deeply regrets that such incidents have occurred even at a major platform widely used by the public."

Park added that the breach was limited to "customer names, emails, phone numbers, delivery addresses and some order histories," and that "payment information, credit card information and customer login information were not included."

음성재생 설정 이동 통신망에서 음성 재생 시 데이터 요금이 발생할 수 있습니다. 글자 수 10,000자 초과 시 일부만 음성으로 제공합니다.
글자크기 설정 파란원을 좌우로 움직이시면 글자크기가 변경 됩니다.

이 글자크기로 변경됩니다.

(예시) 가장 빠른 뉴스가 있고 다양한 정보, 쌍방향 소통이 숨쉬는 다음뉴스를 만나보세요. 다음뉴스는 국내외 주요이슈와 실시간 속보, 문화생활 및 다양한 분야의 뉴스를 입체적으로 전달하고 있습니다.

A major vulnerability in the database of popular online shopping platform Coupang allowed an intruder to access the personal information of more than 30 million users without a valid login, with CEO Park Dae-jun offering an apology to the public.
Coupang CEO Park Dae-jun bows in apology over the company’s massive data leak at the Central Government Complex in Jongno District, central Seoul, on Nov. 30. [YONHAP]

A major vulnerability in the database of popular online shopping platform Coupang allowed an intruder to access the personal information of more than 30 million users without a valid login, according to Vice Prime Minister and Science and ICT Minister Bae Kyung-hoon on Sunday.

Speaking at an emergency meeting with Coupang CEO Park Dae-jun and officials from various ministries at the Central Government Complex in Seoul in the afternoon, Bae confirmed that the intruder “abused an authentication loophole in Coupang’s server” and extracted names, emails, phone numbers and addresses tied to customers’ accounts.

The vice prime minister added that the government “deeply regrets that such incidents have occurred even at a major platform widely used by the public.”

The breach, which authorities believe began in June, went undetected until Nov. 18, when Coupang launched an internal investigation into suspicious activity within the company’s database. The company first announced that just 4,500 accounts were affected, but revised that number days later to 33.7 million — a figure surpassing the active user base of Korea’s dominant online retailer.

Considering that about 24.7 million people use the platform on a regular basis, officials say the leak likely includes data from former users as well, meaning nearly anyone who has ever shopped on the platform could be affected.

In a statement to reporters before the meeting, Park publicly apologized, saying the company was “deeply sorry for causing concern for customers who were affected and the public.” He said Coupang would “work quickly to identify the cause” and “closely cooperate” with investigators to prevent additional harm.

Park added that the breach was limited to “customer names, emails, phone numbers, delivery addresses and some order histories,” and that “payment information, credit card information and customer login information were not included.”

Authorities are examining whether Coupang failed to comply with mandatory security obligations, given the length of time the breach went undetected. Bae said investigators began on-site inspections immediately after the company filed a criminal complaint with police on Tuesday.

Vice Prime Minister and Science and ICT Minister Bae Kyung-hoon speaks at an emergency meeting at the Central Government Complex in Jongno District, central Seoul, on Nov. 30. [YONHAP]

Although Coupang initially insisted “there were no signs of intrusion from outside the company’s internal networks,” police are now investigating the possibility that a former Chinese employee who left the company last month may have extracted the data from overseas.

A police official said authorities were “leaving all possibilities open and verifying the exact circumstances of the leak.”

The incident is already drawing comparisons to the 2011 breach of then-popular social media platform Cyworld, which exposed the personal details of about 35 million users.

Public frustration is mounting as Coupang customers describe slow or confusing notifications of their exposure. The company has sent text alerts to customers warning that their personal data had been exposed, but some users say they received the alerts days after others.

While the full scope how the leaked information could be misused remains unknown, the fallout has already begun.

Since the data breach became widely known, online communities have formed to organize a class-action lawsuit. Some customers have also posted screenshots confirming they had canceled their accounts.

BY MICHAEL LEE [lee.junhyuk@joongang.co.kr]

Copyright © 코리아중앙데일리. 무단전재 및 재배포 금지.