FEDERALItem 1.05 · mandatoryMisuseRetail & ConsumerTechnologyRetailGeneral MerchandisePrivilege AbuseData MishandlingData ExfiltratedCustomer Data InvolvedPIIIDENTITY_BASICCriticalActive
Coupang, Inc.
bd_64f7ce544edaa984 · schema v1 · pii pii-v1
Full breach record for Coupang, Inc. →Coupang, Inc. disclosed under Item 1.05 that its wholly-owned Korean subsidiary Coupang Corp. discovered on November 18, 2025 a cybersecurity incident in which a former employee may have obtained name, phone number, delivery address, and email address associated with up to 33 million customer accounts, plus certain order histories for a subset. No banking, payment-card, or login credentials were compromised. Korean regulators have opened investigations.
SEC clockMateriality determined Dec 15, 2025 → Filed Dec 16, 20251d ✓ SEC 4-day OK28 days discovery → filing
⚠ unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8589743521e54e20SEC 8-Kfiled 2025-12-29(13d gap)Candidate
- bd_a02211a345ae1793SEC 10-K Item 1Cfiled 2026-02-26(72d gap)Verified by operator
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1834584/000183458425000196/cpng-20251215.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Dec 16, 2025
- Raw hash
- 8ff3e4e47cf8027c0301fdf2cd18268b10d37a7ab107ca0140b408db41f54daf
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Coupang, Inc.norm: coupang
- SEC CIK
- 0001834584
- Domain
- coupang.com
Victim entity
- Name
- Coupang, Inc.norm: coupang
- Domain
- coupang.com
- Industry
- Retail & ConsumerllmTechnologyllmNAICS 455219 · All Other General Merchandise Retailers
Incident
- Discovered
- Nov 18, 2025
- Materiality determined
- Dec 15, 2025
- Notification sent
- —
- Affected individuals
- 33,000,000
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage Object
- Threat actor
- Internal
- Regulator citations
- Reported the Incident to relevant Korean regulatory and law enforcement authoritiesKorean regulators have initiated investigations with which Coupang is fully cooperating
- Initial access
- insider_action
Compliance
- Time to disclose
- 28 days(28 days from discovery to filing)
- Compliance flags
- SEC 4-day OK · 1d
- Discovery-date grounding
- unattributedNo provenance was recorded for this discovery date and it matches no other date on the record. It may be correct, but it is not independently grounded.
- Clock breakdown
Statute Window Elapsed Threshold Status SEC Materiality determined: Dec 15, 2025→ Filed: Dec 16, 20251d cal. 4 business days SEC 4-day OK
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.