FEDERALMisuseRetail & ConsumerTechnologyInformationPrivilege AbuseData MishandlingData ExfiltratedCustomer Data InvolvedTargetedPIIIDENTITY_BASICCriticalContained
Coupang, Inc.
bd_a02211a345ae1793 · schema v1 · pii pii-v1
Full breach record for Coupang, Inc. →On November 18, 2025, Coupang Corp. discovered that a former employee had gained unauthorized access to approximately 33 million customer accounts, obtaining names, phone numbers, delivery addresses, and email addresses. Limited data from ~3,000 accounts was saved and later deleted; no payment, credential, or government-ID data was compromised. Coupang disabled the access method, notified Korean regulators and customers, and announced ~$1.2B in customer-compensation vouchers. Securities class actions and a derivative lawsuit followed.
This filing is one of 3 about the same incident.View merged incident
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- bd_8589743521e54e20SEC 8-Kfiled 2025-12-29(59d gap)Candidate
- bd_64f7ce544edaa984SEC 8-Kfiled 2025-12-16(72d gap)Verified by operator
Source provenance
- Source URL
- https://www.sec.gov/Archives/edgar/data/1834584/000183458426000024/cpng-20251231.htm
DisclosureLens renders the full SEC/HHS filing inline below from the originating regulator’s public record (§4.5 fair report privilege).
- Filed at
- Feb 26, 2026
- Raw hash
- adefbe2b6f762528c181b7c434c66bae1eaa5813dc166156d873bbad9016ef2e
Source filing
AI-assisted summary above. The structured extract on this page was generated from the document below. Inspect the source to verify or correct any field.
Reporting entity
- Name
- Coupang, Inc.norm: coupang
- Domain
- coupang.com
Victim entity
- Name
- Coupang, Inc.norm: coupang
- Domain
- coupang.com
- Industry
- Retail & ConsumerllmTechnologyllm
Incident
- Discovered
- Nov 18, 2025
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 33,000,000
- Data types
- PIIIDENTITY_BASIC
- Attack vector
- Insider
- MITRE ATT&CK
- T1078 Valid AccountsT1530 Data from Cloud Storage Object
- Threat actor
- Internal
- Regulator citations
- Reported the Incident to the relevant Korean regulatory and law enforcement authorities
- Initial access
- insider_action
Compliance
- Time to disclose
- 14 weeks(100 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.