Coupang data breach affecting virtually every user draws apology from CEO
전체 맥락을 이해하기 위해서는 본문 보기를 권장합니다.
The vice prime minister added that the government "deeply regrets that such incidents have occurred even at a major platform widely used by the public."
Park added that the breach was limited to "customer names, emails, phone numbers, delivery addresses and some order histories," and that "payment information, credit card information and customer login information were not included."
이 글자크기로 변경됩니다.
(예시) 가장 빠른 뉴스가 있고 다양한 정보, 쌍방향 소통이 숨쉬는 다음뉴스를 만나보세요. 다음뉴스는 국내외 주요이슈와 실시간 속보, 문화생활 및 다양한 분야의 뉴스를 입체적으로 전달하고 있습니다.
![Coupang CEO Park Dae-jun bows in apology over the company’s massive data leak at the Central Government Complex in Jongno District, central Seoul, on Nov. 30. [YONHAP]](https://img3.daumcdn.net/thumb/R658x0.q70/?fname=https://t1.daumcdn.net/news/202511/30/koreajoongangdaily/20251130172148586aclt.jpg)
A major vulnerability in the database of popular online shopping platform Coupang allowed an intruder to access the personal information of more than 30 million users without a valid login, according to Vice Prime Minister and Science and ICT Minister Bae Kyung-hoon on Sunday.
Speaking at an emergency meeting with Coupang CEO Park Dae-jun and officials from various ministries at the Central Government Complex in Seoul in the afternoon, Bae confirmed that the intruder “abused an authentication loophole in Coupang’s server” and extracted names, emails, phone numbers and addresses tied to customers’ accounts.
The vice prime minister added that the government “deeply regrets that such incidents have occurred even at a major platform widely used by the public.”
The breach, which authorities believe began in June, went undetected until Nov. 18, when Coupang launched an internal investigation into suspicious activity within the company’s database. The company first announced that just 4,500 accounts were affected, but revised that number days later to 33.7 million — a figure surpassing the active user base of Korea’s dominant online retailer.
Considering that about 24.7 million people use the platform on a regular basis, officials say the leak likely includes data from former users as well, meaning nearly anyone who has ever shopped on the platform could be affected.
In a statement to reporters before the meeting, Park publicly apologized, saying the company was “deeply sorry for causing concern for customers who were affected and the public.” He said Coupang would “work quickly to identify the cause” and “closely cooperate” with investigators to prevent additional harm.
Park added that the breach was limited to “customer names, emails, phone numbers, delivery addresses and some order histories,” and that “payment information, credit card information and customer login information were not included.”
Authorities are examining whether Coupang failed to comply with mandatory security obligations, given the length of time the breach went undetected. Bae said investigators began on-site inspections immediately after the company filed a criminal complaint with police on Tuesday.
![Vice Prime Minister and Science and ICT Minister Bae Kyung-hoon speaks at an emergency meeting at the Central Government Complex in Jongno District, central Seoul, on Nov. 30. [YONHAP]](https://img3.daumcdn.net/thumb/R658x0.q70/?fname=https://t1.daumcdn.net/news/202511/30/koreajoongangdaily/20251130172150030spgq.jpg)
Although Coupang initially insisted “there were no signs of intrusion from outside the company’s internal networks,” police are now investigating the possibility that a former Chinese employee who left the company last month may have extracted the data from overseas.
A police official said authorities were “leaving all possibilities open and verifying the exact circumstances of the leak.”
The incident is already drawing comparisons to the 2011 breach of then-popular social media platform Cyworld, which exposed the personal details of about 35 million users.
Public frustration is mounting as Coupang customers describe slow or confusing notifications of their exposure. The company has sent text alerts to customers warning that their personal data had been exposed, but some users say they received the alerts days after others.
While the full scope how the leaked information could be misused remains unknown, the fallout has already begun.
Since the data breach became widely known, online communities have formed to organize a class-action lawsuit. Some customers have also posted screenshots confirming they had canceled their accounts.
BY MICHAEL LEE [lee.junhyuk@joongang.co.kr]
Copyright © 코리아중앙데일리. 무단전재 및 재배포 금지.
- More foreigners than ever staying in Korea, as numbers of seasonal workers and tourists rise
- Day 2 of the 2025 MAMA Awards in Hong Kong — as it happened
- Day 1 of the 2025 MAMA Awards in Hong Kong — as it happened
- Jungkook becomes first Korean solo artist to reach 10 billion streams
- Actor Lee Moon-soo, known for film 'Hello Ghost' and TV drama 'Signal,' dies at 76
- Exclusive: Alaska governor says Korea to join $44B LNG project, binding deal set for December
- Communication established with six of 13 satellites after Nuri launch, including primary payload
- Four arrested for hacking surveillance cameras to produce pornography
- North Korean restaurant offering lobster and live music opens in Moscow
- Ukraine holds funeral for Korean and U.S. volunteers killed while fighting Russia