DEFENCE / RADAR

Public snapshot

Coupang·Retail / hospitality·

More than 33.6 million accounts were exposed.

Coupang confirmed exposure of about 33.7 million South Korean customer accounts and reported the incident to Korean authorities. The attached record does not establish the complete downstream scope.

Report freshness and timeline

Incident occurred
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Organization confirmed
Mechanism
Reported cause: Lax oversight of authentication systems
Consequence
Reported: More than 33.6 million accounts were exposed.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Coupang
Industry
Retail / hospitality
Disclosed
Event date
Entry path
Exploited Vulnerability
Affected asset
Coupang servers
Country
KR
Data involved
Personal data
Reported impact
Data exposure
Attached evidence
4 independent domains · 4 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved exploited vulnerability.

    ConfidenceSecondary
    Exact excerpt

    gained access to Coupang's servers by exploiting vulnerability in its authentication system

    en.yna.co.kr · Feb 10
    E1
  2. 02

    Reported cause

    Lax oversight of authentication systems

    ConfidenceSecondary
    Exact excerpt

    citing lax oversight of authentication systems

    reuters.com · Feb 10
    E2
  3. 03

    Reached

    Coupang servers

    ConfidenceSecondary
    Exact excerpt

    gained access to Coupang's servers

    en.yna.co.kr · Feb 10
    E3
  4. 04

    Observed

    More than 33.6 million accounts were exposed.

    ConfidenceProbable
    Exact excerpt

    over 33.6 million accounts have been exposed

    en.yna.co.kr · Feb 10
    E4

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • That a Defence review would have prevented this incident

4)Relevance to your product

A reachable dependency can turn one missed update into a path across systems.

This pattern applies when…

  • Products whose authentication systems protect large customer datasets.

Diagnostic questions

  1. Which deployed components carry a known exploitable vulnerability?
  2. Can a stale dependency remain reachable from a public product path?
  3. Is the deployed software inventory complete enough to act on quickly?

This incident does not establish your product's risk.

5)Sector context — Retail / hospitality

57 incident threads in the 365-day public record
  1. 1 incident threads
  2. 1 incident threads
  3. 2 incident threads
  4. 1 incident threads
  5. 6 incident threads
  6. 8 incident threads
  7. 6 incident threads
  8. 8 incident threads
  9. 5 incident threads
  10. 4 incident threads
  11. 9 incident threads
  12. 6 incident threads
Same incident family
23
Data breach / intrusion
Confirmed share
32%
18 confirmed · 39 reported
Display family
Data breach
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Retail / hospitality in Radar →

6)Defence control mapping

Relevant control area

Dependency and SBOM control area

  • Which deployed components carry a known exploitable vulnerability?
  • Can a stale dependency remain reachable from a public product path?
  • Is the deployed software inventory complete enough to act on quickly?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.
  • This control is outside the current public external web/API review offer.

7)Public evidence ledger

4 attached sources across 4 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E1, E3, E4
    en.yna.co.kr(3rd LD) Joint probe finds 33.6 mln accounts exposed in Coupang data breach, dwarfing initial claim | Yonhap News AgencyOther public report · Feb 10 · Cited
    Other public reportCited
    Exact excerpt
    names, phone numbers, email addresses and delivery details
  2. E2
    reuters.comSouth Korea blames Coupang data breach on ...Established press · Feb 10 · Cited
    Established pressCited
    Exact excerpt
    citing lax oversight of authentication systems
  3. S3
    techcrunch.comKorea's Coupang says data breach exposed nearly 34M customers' personal information | TechCrunchEstablished press · Dec 01 · Attached
    Established pressAttached
  4. S4
    aboutcoupang.comCoupang, Inc. | Update on the November 29 personal information incidentOther public report · Feb 24 · Attached
    Other public reportAttached

Discuss the external product boundary around this control.

Defence's current public offer is limited to authorized external web/API behavior; it is not a complete SBOM or dependency audit.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →