Coupang, Inc.
bd_64f7ce544edaa984 · schema v1 · pii pii-v1
Full breach record for Coupang, Inc. →Coupang, Inc. disclosed under Item 1.05 that its wholly-owned Korean subsidiary Coupang Corp. discovered on November 18, 2025 a cybersecurity incident in which a former employee may have obtained name, phone number, delivery address, and email address associated with up to 33 million customer accounts, plus certain order histories for a subset. No banking, payment-card, or login credentials were compromised. Korean regulators have opened investigations.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 18, 2025
Discovered
Dec 15, 2025
Scope determined
Dec 16, 2025
Filed
vs. sector median
4 wks faster
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- SEC 8-Kbd_8589743521e54e202025-12-29 · +13dCandidate
- SEC 10-K Item 1Cbd_a02211a345ae17932026-02-26 · +72dVerified by operator
Filing propagation · 3 filings
View merged incident ↗Pattern: first filing Dec 16, last Feb 26 — a 72-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.