SEOUL — Nearly a year after one of South Korea’s most damaging corporate data breaches exposed personal information linked to tens of millions of people, Coupang is building a new layer of outside oversight around its cybersecurity operations.
The e-commerce giant said Tuesday it had formally launched an information security advisory committee featuring seven outside specialists in cybersecurity, law, management and information technology.
Their job sounds straightforward:
Review Coupang’s security policies.
Track new cyber threats.
Monitor regulatory changes.
And tell one of South Korea’s biggest technology companies where its defenses still fall short.
But the committee is being formed against an extraordinary backdrop.
Last year’s breach exposed data associated with more than 33 million Coupang users, eventually led regulators to conclude that fundamental security controls had failed, triggered hundreds of billions of won in penalties and raised an uncomfortable question that still hangs over the company:
How did someone with knowledge of Coupang’s systems manage to access personal data on such an enormous scale without being stopped sooner?
That is the problem the new committee inherits.
Seven outside experts — and Coupang’s own security chief
The newly established committee will meet quarterly, according to Coupang.
It is intended to provide more objective scrutiny of internal security practices and make recommendations that can be incorporated into Coupang’s operational policies.
The panel is co-chaired by Heo Sung-wook, chairman of the Korea Chief Privacy Officers’ Forum, and Brett Matthes, Coupang’s chief information security officer.
Heo previously served as director general of the Network Policy Office at South Korea’s Ministry of Science and ICT and as president of the National IT Industry Promotion Agency.
The seven outside members include legal specialists, academics and cybersecurity experts from organizations and universities including Kim & Chang, Shin & Kim, Ajou University, Kyung Hee University, ChungAng University and Seoul National University of Science and Technology.
Coupang says the group will study emerging threats, changes to laws and regulations and unresolved security issues while advising management on broader information-protection policy.
The company says it plans to incorporate the committee’s recommendations into its internal systems.
That promise will now be closely watched.
Because regulators have already documented what happened when Coupang’s previous controls failed.
The breach initially looked tiny
The scandal exploded in November 2025.
Coupang initially disclosed unauthorized exposure involving only about 4,500 customer accounts.
Within days, that number changed dramatically.
On November 29, the company said information associated with approximately 33.7 million customer accounts had been exposed.
Names, email addresses, phone numbers, delivery addresses and some order-related information were affected.
Coupang said payment information, credit-card details and login credentials were not accessed.
The scale was staggering.
Coupang had about 24.7 million active Product Commerce customers during the third quarter of 2025, meaning the exposure covered information associated with essentially its entire historical Korean customer base and, in some cases, people who were not even account holders themselves.
That last detail later became important.
People without Coupang accounts were affected too
South Korea’s Personal Information Protection Commission eventually concluded that the exposed information extended beyond registered users.
Its investigation found data involving around 33.22 million Coupang users.
But shipping records also contained personal details relating to approximately 4.33 million third parties — people such as relatives, friends or other recipients whose information customers had entered for deliveries.
Those records could include names, telephone numbers and addresses.
In some instances, regulators said the exposed information included order details and apartment or building entrance passwords.
That explains why some later Korean reporting described the incident as involving information on more than 37 million people, while Coupang’s original headline figure referred to around 33.7 million customer accounts.
Both figures describe different populations.
And neither should be casually substituted for the other.
The regulator says this was not an elite hacking operation
Perhaps the most damaging government conclusion came in June.
South Korea’s privacy regulator said the breach resulted from “inadequate management of baseline personal data protection” rather than sophisticated hacking techniques.
According to the PIPC, the person responsible was a former employee who had been able to access authentication signing keys while working at the company.
The former employee later allegedly used forged authentication tokens to access areas of Coupang’s systems containing personal information.
The regulator said Coupang had allowed access to signing keys in plaintext even in circumstances where access to a backup key was unnecessary.
More seriously, it found that the company failed to immediately renew or destroy certain signing keys after the employee left.
In security terms, that finding goes to the heart of the scandal.
The attacker did not necessarily have to defeat a futuristic cyberdefense system from the outside.
Regulators say weaknesses in how authentication credentials were managed created an opening from within.
Warning signs appeared — but were not enough to stop it
The PIPC also found that abnormal traffic appeared on pages containing personal information during the period of unauthorized activity.
But Coupang had not established sufficient thresholds to automatically block suspicious activity on those pages and did not separately analyze certain anomalies, according to the regulator.
The result was an intrusion that persisted for months.
Coupang originally said unauthorized access appeared to have occurred through overseas servers beginning on June 24, 2025.
The later PIPC investigation traced unauthorized access activity from April through November 2025, creating a broader official timeline than the company initially disclosed.
The episode became one of the clearest examples in recent Korean corporate history of why cybersecurity is not only about buying better software.
It is also about access controls.
Credential management.
Employee departures.
Anomaly detection.
Internal governance.
And making sure somebody acts when a system begins behaving strangely.
The breach generated roughly 148 million page accesses
A separate joint public-private investigation led by South Korea’s science ministry examined approximately 25.6 terabytes of web-access logs.
Investigators concluded that the relevant delivery section of Coupang’s site had been viewed about 148 million times during the unauthorized activity.
The investigators said forged authentication passes allowed normal verification procedures to be bypassed.
That number — 148 million — helps illustrate why the case became such a major regulatory event.
This was not an attacker manually opening a handful of customer profiles.
It involved automated access at a scale capable of sweeping through an enormous database.
Coupang has disputed parts of the government’s interpretation.
The company has maintained that while information from more than 33 million accounts was accessed, forensic evidence indicated that the former employee retained information from only around 3,000 accounts, subsequently deleted it and did not distribute it to others.
That became one of the most contentious disputes between Coupang and Korean authorities.
Regulators rejected Coupang’s narrower interpretation
South Korean authorities distinguished between data that was accessed or exposed and data the attacker may ultimately have saved on personal devices.
The government maintained that the larger 33 million-plus figure remained the relevant measure of the breach because information was improperly accessed from Coupang’s systems.
Science Minister Bae Kyung-hoon publicly reaffirmed that position after Coupang promoted its approximately 3,000-account retention figure.
The difference is crucial.
Saying the hacker may have saved data from around 3,000 accounts is not the same as saying only 3,000 accounts were breached.
Coupang’s systems were accessed on a dramatically larger scale.
The two sides therefore disagreed less about whether tens of millions of accounts were touched than about what level of exposure should determine the public understanding of the incident.
Then came a record penalty
In June, the Personal Information Protection Commission imposed the largest privacy penalty in South Korean history.
The headline number was approximately ₩624.7 billion, then worth around US$410 million.
But that figure needs careful breakdown.
About ₩423.6 billion was imposed specifically because of the massive data breach and failures to implement sufficient safeguards.
A separate ₩201.1 billion penalty concerned another case in which Coupang allegedly collected online behavioral data from about 11.17 million users without proper authorization through activities associated with its Coupang Partners advertising ecosystem.
The two penalties were announced together.
They were not for the same violation.
Coupang was additionally ordered to make changes to key management, access control, breach notification and internal privacy governance.
The company has said it disagrees with aspects of the regulator’s findings and intends to seek judicial relief.
In a U.S. regulatory filing, Coupang said it planned to challenge the PIPC action in the Seoul Administrative Court.
So the penalties are significant, but the legal fight is not necessarily finished.
Regulators also criticized Coupang’s internal privacy governance
One regulatory finding is particularly relevant to Tuesday’s new advisory committee.
The PIPC said Coupang’s chief privacy officer had been excluded from an internal investigation and information-disclosure process carried out in December 2025.
The regulator argued that this undermined the independence and role of the privacy officer — a position that is supposed to provide internal oversight over how personal data is handled.
That history raises an obvious test for the new committee.
It is one thing to appoint respected outside specialists.
It is another to give them meaningful access to information and the institutional authority to challenge executives when necessary.
Coupang says the committee will provide objective reviews and that its recommendations will feed into company policy.
But the committee is advisory.
It is not an independent regulator.
It cannot impose fines.
And because Coupang’s own chief information security officer serves as co-chair, questions about how independent its oversight will be can ultimately be answered only by what happens when outside members disagree with management.
Consumers were offered ₩1.68 trillion worth of vouchers
Coupang also attempted to repair its relationship with customers through compensation.
In December, the company announced a package valued at more than ₩1.68 trillion, covering roughly 33.7 million affected customers.
Each eligible person was offered vouchers with a nominal total value of ₩50,000 across Coupang services.
But the structure immediately became controversial.
Only ₩5,000 applied directly to Coupang’s main shopping service.
Another ₩5,000 applied to Coupang Eats.
The remaining ₩40,000 was split between Coupang Travel and the company’s R.LUX beauty and luxury business.
Consumer groups criticized the package, arguing that much of the supposed compensation functioned more like promotional coupons designed to encourage additional spending.
That criticism created an uncomfortable optics problem:
A company trying to compensate customers for a data breach was asking them to return to its ecosystem to receive much of the advertised value.
A consumer panel later ordered actual damages for 50 people
In July, Korea’s Consumer Dispute Mediation Committee went further.
It ordered Coupang to provide ₩100,000 per person in cash or Coupang Cash to 50 consumers who had jointly applied for mediation.
The committee pointed to the sensitivity of information involved, including addresses, order histories and apartment entrance codes, and recognized psychological harm resulting from the breach.
But the ruling should not be overstated.
It involved the 50 people who filed the collective mediation case.
It did not automatically award ₩100,000 to every one of the tens of millions of people whose information was affected.
Still, the decision was symbolically important because it represented formal recognition by a Korean consumer dispute body that the breach could create compensable harm.
And yet customers have not abandoned Coupang
Perhaps the most surprising part of the story is what happened commercially.
Despite months of criticism, government investigations and record penalties, Coupang remains deeply embedded in South Korean daily life.
Data reported by Aju Press showed estimated credit- and debit-card payments on Coupang reached approximately ₩4.93 trillion in August 2026, up 12.6% from the same month a year earlier.
Estimated spending had already climbed above ₩5 trillion in July.
That suggests a striking disconnect between reputational damage and consumer behavior.
People may be angry about privacy.
But they still want overnight deliveries.
That is one reason rebuilding “trust” is difficult to measure.
Coupang does not necessarily need every customer to publicly forgive it.
It needs them to believe that staying is safe enough.
The new committee is therefore about more than cybersecurity
Coupang says the committee will help build security standards that reach or exceed leading global practices.
The panel’s quarterly meetings will examine new cyber threats, regulatory developments and unresolved security issues.
Those are sensible goals.
But after what regulators documented, the company’s challenge goes beyond technology.
It must demonstrate that security recommendations can override convenience.
That authentication keys are managed rigorously.
That unusual system activity cannot remain unexplained for months.
That privacy officers can operate independently.
That departing employees immediately lose sensitive access.
And that customers are told quickly when something has gone wrong.
Those are governance questions as much as engineering ones.
Seven experts can give advice — but implementation is the real test
Corporate advisory boards are relatively easy to create after a crisis.
The difficult part comes later.
What happens when the committee recommends an expensive redesign?
What happens when stronger controls slow down internal systems?
What happens when an outside expert says a popular feature creates unacceptable privacy risks?
Does management implement the recommendation?
Modify it?
Or ignore it?
Coupang says the panel’s expertise will be incorporated into internal security processes.
The public has no reason yet to assume otherwise.
But after one of the largest data breaches in South Korean history, trust is unlikely to be rebuilt by committee membership alone.
It will be rebuilt — or lost again — through what happens the next time somebody tries to get past Coupang’s defenses.
Because the most damaging lesson from the breach was its simplicity
The frightening part of Coupang’s breach is not that an unstoppable cyberweapon defeated a world-class company.
According to South Korea’s own privacy regulator, the opposite was closer to the truth.
Signing keys were not sufficiently protected.
Credentials were not properly invalidated after an employee left.
Unusual traffic was not adequately blocked or investigated.
And millions of people’s information became accessible.
That is why Tuesday’s committee matters.
Not because seven experts can guarantee Coupang will never be hacked again.
No serious company can make that promise.
The more realistic test is whether Coupang becomes much harder to compromise — and whether future warning signs trigger action before tens of millions of records are exposed.
Coupang has now built the advisory panel it says will help restore confidence. The cliffhanger is whether those experts will merely review its security — or have enough influence to change the company before the next warning arrives.

Leave a Reply