Coupang, Inc.
bd_a02211a345ae1793 · schema v1 · pii pii-v1
Full breach record for Coupang, Inc. →On November 18, 2025, Coupang Corp. discovered that a former employee had gained unauthorized access to approximately 33 million customer accounts, obtaining names, phone numbers, delivery addresses, and email addresses. Limited data from ~3,000 accounts was saved and later deleted; no payment, credential, or government-ID data was compromised. Coupang disabled the access method, notified Korean regulators and customers, and announced ~$1.2B in customer-compensation vouchers. Securities class actions and a derivative lawsuit followed.
J jump to incidentP pin to compareR raw source
Incident timeline
Nov 18, 2025
Discovered
Feb 26, 2026
Filed
vs. sector median
+7 wks slower
Linked disclosures
Why this link?Regulatory filings (2) · sorted by filing gap
- SEC 8-Kbd_8589743521e54e202025-12-29 · +59dCandidate
- SEC 8-Kbd_64f7ce544edaa9842025-12-16 · +72dVerified by operator
Filing propagation · 3 filings
View merged incident ↗Pattern: first filing Dec 16, last Feb 26 — a 72-day rolling notification. Rolling spreads often mean counsel is filing as thresholds trip per state. Why this link?
Evidence ladder
Attacker assertion only. Establishes: claim date, group, alleged victim.
Unlocks: incident narrative, operational impact. Still no compliance clock.
Unlocks: discovery date, data types, affected count, compliance clock.
Unlocks: materiality, stated response, full audit trail. Ceiling removed.