Coupang·Retail / hospitality·
Customer information was leaked.
South Korea's investigation confirmed leakage of 33,673,817 Coupang name and email records through web pages. The attached record does not establish the complete downstream scope.
Report freshness and timeline
- Reported incident date
- First disclosed
- Latest attached source
- Radar data checked
Coverage window — Dataset generated Aug 30, 2026, 12:03 UTC
Executive incident brief
- Incident confirmation
- Regulator confirmed
- Mechanism
- Reported cause: Poor management of valid authentication keys
- Consequence
- Reported: Customer information was leaked.
- Scope
- The complete extent is not established by this record.
1)Incident fact sheet
- Organization
- Coupang
- Industry
- Retail / hospitality
- Disclosed
- Event date
- Entry path
- Exploited Vulnerability
- Affected asset
- Coupang servers
- Country
- KR
- Data involved
- Personal data
- Reported impact
- Data exposure
- Attached evidence
- 5 independent domains · 5 sources
2)Evidence-backed incident path
- 01
Entry path
Initial access involved exploited vulnerability.
ConfidenceSecondaryExact excerpt
E1“the attacker exploited an authentication vulnerability in Coupang’s servers, bypassing the normal login process”
csoonline.com · Date not established - 02
Reported cause
Poor management of valid authentication keys
ConfidenceSecondaryExact excerpt
E2“A prolonged lack of management of valid authentication keys”
csoonline.com · Date not established - 03
Reached
Coupang servers
ConfidenceSecondaryExact excerpt
E3“authentication vulnerability in Coupang’s servers”
csoonline.com · Date not established - 04
Observed
Customer information was leaked.
ConfidenceProbableExact excerpt
E4“leaking customer information”
csoonline.com · Date not established
3)Impact and scope ledger
Established
Supported at the stated evidence level.
Reported
Present in public reporting; not independently established by Radar.
Not publicly established
No qualifying public evidence in the attached record.
- The supplied source is secondary rather than regulator-primary
- That a Defence review would have prevented this incident
4)Relevance to your product
A reachable dependency can turn one missed update into a path across systems.
This pattern applies when…
- Products that expose account data through web pages or application endpoints.
- Teams that test authentication bypass and record-level access controls.
Diagnostic questions
- Which deployed components carry a known exploitable vulnerability?
- Can a stale dependency remain reachable from a public product path?
- Is the deployed software inventory complete enough to act on quickly?
This incident does not establish your product's risk.
5)Sector context — Retail / hospitality
- 1 incident threads
- 1 incident threads
- 2 incident threads
- 1 incident threads
- 6 incident threads
- 8 incident threads
- 6 incident threads
- 8 incident threads
- 5 incident threads
- 4 incident threads
- 9 incident threads
- 6 incident threads
- Same incident family
- 2 Web, API or logic failure
- Confirmed share
- 32% 18 confirmed · 39 reported
- Display family
- Vulnerability exploitation Used for Radar's public chart taxonomy
Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.
Explore Retail / hospitality in Radar →6)Defence control mapping
Relevant control area
Dependency and SBOM control area
- Which deployed components carry a known exploitable vulnerability?
- Can a stale dependency remain reachable from a public product path?
- Is the deployed software inventory complete enough to act on quickly?
What cannot be concluded
- This incident does not predict an individual product's risk.
- A mapped control does not establish that a Defence review would have prevented the event.
- This control is outside the current public external web/API review offer.
7)Public evidence ledger
5 attached sources across 5 independent domains. No attached source is marked as an organization or regulator primary source.
Discuss the external product boundary around this control.
Defence's current public offer is limited to authorized external web/API behavior; it is not a complete SBOM or dependency audit.