Description

South Korea’s largest retailer, Coupang, has disclosed a major data breach that exposed the personal information of 33.7 million customers. The incident occurred on June 24, 2025, but the company only detected the unauthorized access on November 18, 2025, initially believing only 4,500 accounts were affected. Further investigation revealed the breach was far more extensive, exposing customer names, phone numbers, email addresses, physical addresses, and order history. Fortunately, payment information and passwords were not compromised. This incident underscores the growing risks associated with large-scale data storage and the consequences of improper access control. Reports suggest that a former employee may have used unrevoked internal access tokens, highlighting potential insider threats and inadequate offboarding processes. With Coupang serving millions across South Korea, the breach raises serious concerns about data management, access monitoring, and internal security hygiene within large organizations. It also follows another massive breach earlier this year involving SK Telecom, suggesting a trend of escalating cybersecurity challenges in the region. To mitigate risks, impacted customers are advised to stay alert for phishing attempts impersonating Coupang through calls, SMS, or emails. Organizations should enforce strict access control policies, regularly revoke unused credentials, audit internal privileges, and deploy behavioral monitoring tools to detect suspicious access patterns. Security teams must strengthen incident response readiness, ensure timely patching, and maintain strong data protection controls especially in environments handling high volumes of sensitive customer information.