DEFENCE / RADAR

Public snapshot

Coupang·Retail / hospitality·

Customer information was leaked.

South Korea's investigation confirmed leakage of 33,673,817 Coupang name and email records through web pages. The attached record does not establish the complete downstream scope.

Report freshness and timeline

Reported incident date
First disclosed
Latest attached source
Radar data checked

Coverage windowDataset generated Aug 30, 2026, 12:03 UTC

Executive incident brief

Incident confirmation
Regulator confirmed
Mechanism
Reported cause: Poor management of valid authentication keys
Consequence
Reported: Customer information was leaked.
Scope
The complete extent is not established by this record.

1)Incident fact sheet

Organization
Coupang
Industry
Retail / hospitality
Disclosed
Event date
Entry path
Exploited Vulnerability
Affected asset
Coupang servers
Country
KR
Data involved
Personal data
Reported impact
Data exposure
Attached evidence
5 independent domains · 5 sources

2)Evidence-backed incident path

  1. 01

    Entry path

    Initial access involved exploited vulnerability.

    ConfidenceSecondary
    Exact excerpt

    the attacker exploited an authentication vulnerability in Coupang’s servers, bypassing the normal login process

    csoonline.com · Date not established
    E1
  2. 02

    Reported cause

    Poor management of valid authentication keys

    ConfidenceSecondary
    Exact excerpt

    A prolonged lack of management of valid authentication keys

    csoonline.com · Date not established
    E2
  3. 03

    Reached

    Coupang servers

    ConfidenceSecondary
    Exact excerpt

    authentication vulnerability in Coupang’s servers

    csoonline.com · Date not established
    E3
  4. 04

    Observed

    Customer information was leaked.

    ConfidenceProbable
    Exact excerpt

    leaking customer information

    csoonline.com · Date not established
    E4

3)Impact and scope ledger

Not publicly established

No qualifying public evidence in the attached record.

  • The supplied source is secondary rather than regulator-primary
  • That a Defence review would have prevented this incident

4)Relevance to your product

A reachable dependency can turn one missed update into a path across systems.

This pattern applies when…

  • Products that expose account data through web pages or application endpoints.
  • Teams that test authentication bypass and record-level access controls.

Diagnostic questions

  1. Which deployed components carry a known exploitable vulnerability?
  2. Can a stale dependency remain reachable from a public product path?
  3. Is the deployed software inventory complete enough to act on quickly?

This incident does not establish your product's risk.

5)Sector context — Retail / hospitality

57 incident threads in the 365-day public record
  1. 1 incident threads
  2. 1 incident threads
  3. 2 incident threads
  4. 1 incident threads
  5. 6 incident threads
  6. 8 incident threads
  7. 6 incident threads
  8. 8 incident threads
  9. 5 incident threads
  10. 4 incident threads
  11. 9 incident threads
  12. 6 incident threads
Same incident family
2
Web, API or logic failure
Confirmed share
32%
18 confirmed · 39 reported
Display family
Vulnerability exploitation
Used for Radar's public chart taxonomy

Publicly disclosed incidents and reports from to . Historical discovery is partial and does not measure breach probability.

Explore Retail / hospitality in Radar →

6)Defence control mapping

Relevant control area

Dependency and SBOM control area

  • Which deployed components carry a known exploitable vulnerability?
  • Can a stale dependency remain reachable from a public product path?
  • Is the deployed software inventory complete enough to act on quickly?

What cannot be concluded

  • This incident does not predict an individual product's risk.
  • A mapped control does not establish that a Defence review would have prevented the event.
  • This control is outside the current public external web/API review offer.

7)Public evidence ledger

5 attached sources across 5 independent domains. No attached source is marked as an organization or regulator primary source.

  1. E1, E2, E3, E4
    csoonline.comCoupang breach of 33.7 million accounts allegedly involved engineer insiderEstablished press · Date not established · Cited
    Established pressCited
    Exact excerpt
    names, email addresses, shipping address lists, and some order information
  2. S2
    chosun.comCoupang Breach Exposes 33.7 Million User RecordsOther public report · Feb 10 · Attached
    Other public reportAttached
  3. S3
    biz.chosun.comCoupang security lapses expose 33.7M users; South Korea orders probe and fines - CHOSUNBIZOther public report · Feb 10 · Attached
    Other public reportAttached
  4. S4
    khan.co.kr“The Coupang incident was an accident caused by poor management”···The scale of the personal data leak is likely to grow further - 경향신문Other public report · Feb 10 · Attached
    Other public reportAttached
  5. S5
    digitaltoday.co.krSouth Korea confirms leak of 33.7 million Coupang accountsOther public report · Feb 10 · Attached
    Other public reportAttached

Discuss the external product boundary around this control.

Defence's current public offer is limited to authorized external web/API behavior; it is not a complete SBOM or dependency audit.

Each report separates what public reporting establishes from what remains unknown. It does not turn another company's incident into a prediction of your risk. Dataset coverage: . View methodology →