Coupang·Retail / hospitality·
More than 33.6 million accounts were exposed.
Coupang confirmed exposure of about 33.7 million South Korean customer accounts and reported the incident to Korean authorities. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- Incident occurred
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Organization confirmed
- Mechanism
- Reported cause: Lax oversight of authentication systems
- Consequence
- Reported: More than 33.6 million accounts were exposed.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Coupang
- Industry
- Retail / hospitality
- Disclosed
- Event date
- Entry path
- Exploited Vulnerability
- Affected asset
- Coupang servers
- Country
- KR
- Data involved
- Personal data
- Reported impact
- Data exposure
- Attached evidence
- 4 independent domains · 4 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved exploited vulnerability.
ConfidenceSecondaryExact excerpt
E1“gained access to Coupang's servers by exploiting vulnerability in its authentication system”
en.yna.co.kr · Feb 10 - 02
Reported cause
Lax oversight of authentication systems
ConfidenceSecondaryExact excerpt
E2“citing lax oversight of authentication systems”
reuters.com · Feb 10 - 03
Reached
Coupang servers
ConfidenceSecondaryExact excerpt
E3“gained access to Coupang's servers”
en.yna.co.kr · Feb 10 - 04
Observed
More than 33.6 million accounts were exposed.
ConfidenceProbableExact excerpt
E4“over 33.6 million accounts have been exposed”
en.yna.co.kr · Feb 10
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- That a Defence review would have prevented this incident
4)Relevance to your product
A reachable dependency can turn one missed update into a path across systems.
This pattern applies when…
- Products whose authentication systems protect large customer datasets.
Diagnostic questions
- Which deployed components carry a known exploitable vulnerability?
- Can a stale dependency remain reachable from a public product path?
- Is the deployed software inventory complete enough to act on quickly?
This incident does not establish your product's risk.
5)Sector context — Retail / hospitality
- 1 incident threads
- 1 incident threads
- 2 incident threads
- 1 incident threads
- 6 incident threads
- 8 incident threads
- 6 incident threads
- 8 incident threads
- 5 incident threads
- 4 incident threads
- 9 incident threads
- 6 incident threads
- Same incident family
- 23 Data breach / intrusion
- Confirmed share
- 32% 18 confirmed · 39 reported
- Display family
- Data breach Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Retail / hospitality in Radar →6)Defence control mapping
Relevant control area
Dependency and SBOM control area
- Which deployed components carry a known exploitable vulnerability?
- Can a stale dependency remain reachable from a public product path?
- Is the deployed software inventory complete enough to act on quickly?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
- This control is outside the current public external web/API review offer.
7)Public evidence ledger
4 attached sources across 4 independent domains. No attached source is marked as an organization or regulator primary source.
- E1, E3, E4en.yna.co.kr(3rd LD) Joint probe finds 33.6 mln accounts exposed in Coupang data breach, dwarfing initial claim | Yonhap News AgencyOther public report · Feb 10 · CitedOther public reportCited
Exact excerpt
“names, phone numbers, email addresses and delivery details”
- E2reuters.comSouth Korea blames Coupang data breach on ...Established press · Feb 10 · CitedEstablished pressCited
Exact excerpt
“citing lax oversight of authentication systems”
Discuss the external product boundary around this control.
Defence's current public offer is limited to authorized external web/API behavior; it is not a complete SBOM or dependency audit.