Coupang, Inc.
ent_019e413917a0cce0924bfc500449b104
Disclosures
3
SEC 10-K Item 1C · SEC 8-K · 1 jurisdiction
Incidents
1
filings grouped by incident
Max affected reported
33,000,000
as filed · SEC 10-K Item 1C FEDERAL
Leak-site claims
0
none in sample
Identity resolution
- Canonical name
- Coupang, Inc.
- Normalized
- coupang— dedupe via name-norm; Microsoft / MSFT collapse to one row
- GLEIF LEI
- 549300XR4L1D80AK4W76
- SEC EDGAR CIK
- 0001834584
- Domain
- coupang.com
Disclosure history (3)newest first
- FEDERALSEC 10-K Item 1Cas victim2026-02-26
On November 18, 2025, Coupang Corp. discovered that a former employee had gained unauthorized access to approximately 33 million customer accounts, obtaining names, phone numbers, delivery addresses, and email addresses. Limited data from ~3,000 accounts was saved and later deleted; no payment, credential, or government-ID data was compromised. Coupang disabled the access method, notified Korean regulators and customers, and announced ~$1.2B in customer-compensation vouchers. Securities class actions and a derivative lawsuit followed.
- FEDERALSEC 8-Kas victim2025-12-29
Coupang, Inc. filed Form 8-K/A (Amendment No. 1) updating disclosure of a cybersecurity incident at its wholly-owned Korean subsidiary, Coupang Corp. Approximately 33 million accounts were accessed; the perpetrator saved limited data from approximately 3,000 customer accounts, which has been deleted and not shared with a third party. The perpetrator has been identified and is cooperating. Coupang announced a ~1.685 trillion KRW (~$1.2 billion) customer voucher compensation program starting January 15, 2026.
- FEDERALSEC 8-Kas victim2025-12-16
Coupang, Inc. disclosed under Item 1.05 that its wholly-owned Korean subsidiary Coupang Corp. discovered on November 18, 2025 a cybersecurity incident in which a former employee may have obtained name, phone number, delivery address, and email address associated with up to 33 million customer accounts, plus certain order histories for a subset. No banking, payment-card, or login credentials were compromised. Korean regulators have opened investigations.