Coupang Launches External Security Committee After Massive Data Leak

Business

Coupang Launches External Security Committee After Massive Data Leak

COUPANG BRINGS IN OUTSIDE SECURITY EXPERTS

Coupang is stepping up its cybersecurity response after its massive customer-data breach by establishing an external information security advisory committee designed to provide independent scrutiny of the company’s security practices.

The committee was formally launched on September 15, 2026, and consists of seven outside experts specializing in information security, law, management and information technology. Coupang said the panel will assess its security policies objectively and advise on measures to strengthen protection of customer information.

The move represents one of the company’s latest efforts to rebuild confidence following a breach that affected more than 33 million users, one of the largest data-security incidents in South Korea.

WHO IS ON THE NEW COMMITTEE?

The new advisory body brings together specialists from different fields rather than relying solely on Coupang’s internal security organization.

Heo Seong-wook, chairman of the Korea CPO Forum and a former senior official at South Korea’s Ministry of Science and ICT, was appointed co-chair alongside Brett Mathis, Coupang’s chief information security officer.

Other members include legal and academic experts with backgrounds in cybersecurity, IT, management and information-protection policy.

The composition is significant because the company says the committee is intended to provide a more objective and credible assessment of its security framework following the breach.

WHY COUPANG NEEDED A NEW SECURITY OVERHAUL

The committee comes after a major data breach disclosed in late 2025 triggered a lengthy investigation in South Korea.

Government investigations subsequently determined that the incident involved an enormous amount of customer information. Reuters previously reported that the breach affected 33.7 million customers, while investigations examined how attackers were able to exploit authentication vulnerabilities and maintain unauthorized access.

The incident placed Coupang under intense scrutiny because of the sheer scale of the affected customer base.

The company has since faced pressure to improve its security systems, strengthen internal controls and demonstrate that customer information is better protected.

THE NEW PANEL WILL REVIEW SECURITY ON A REGULAR BASIS

The committee is not being established as a one-time crisis response.

According to Seoul Economic Daily, the external experts are expected to conduct quarterly reviews, giving the company an ongoing outside assessment of its information-security measures.

That could prove important because cybersecurity risks can change quickly. Regular reviews can help identify weaknesses before they develop into larger incidents and can provide management with an independent assessment of whether security improvements are actually working.

For Coupang, the challenge is therefore not simply responding to the previous breach—but convincing customers and regulators that lessons from the incident are being converted into lasting changes.

THE BREACH HAS ALSO CREATED A WIDER POLITICAL AND REGULATORY FIGHT

Coupang’s data-security crisis has extended beyond cybersecurity.

South Korean authorities have rejected allegations from a U.S. congressional report that the government unfairly targeted Coupang or discriminated against U.S. companies during its investigations.

South Korea’s presidential office has maintained that its laws and regulations are applied regardless of a company’s nationality.

That dispute has added another layer to an already complicated case involving data protection, corporate responsibility and cross-border business relations.

A RECORD FINE ADDED TO THE PRESSURE

The breach also resulted in significant regulatory consequences.

In June 2026, South Korean authorities imposed a record fine of about $408 million on Coupang over the data leak, according to Al Jazeera’s reporting. The incident had been found to involve personal information belonging to more than 30 million people.

The financial penalty underscores the seriousness of the incident—but the bigger challenge for Coupang may be restoring customer confidence.

Consumers expect e-commerce platforms to protect information that can include names, contact details, addresses and transaction-related data.

WHY THE NEW COMMITTEE MATTERS

Creating an outside advisory panel does not erase the breach, nor does it guarantee that another incident cannot happen.

But it does signal a shift toward independent oversight of Coupang’s information-security practices.

The company now has to demonstrate that the committee’s recommendations translate into stronger systems, better access controls and more effective protection of customer data.

That distinction will be crucial.

After a breach affecting tens of millions of people, customers are unlikely to judge Coupang simply by the creation of another committee. They will ultimately judge the company by whether its security practices measurably improve.

COUPANG’S NEXT TEST: REBUILDING TRUST

The launch of the security committee marks another chapter in Coupang’s long-running response to its data crisis.

The company has already faced investigations, regulatory scrutiny and political controversy. Now it is putting external specialists inside a formal oversight structure to examine how its security operation should evolve.

The committee can provide expertise and independent scrutiny—but rebuilding trust will depend on what Coupang does with that advice.

For a company serving millions of customers, the stakes are enormous: the next test will not be announcing stronger security, but proving that customers’ information is actually safer.

Leave a Reply

Your email address will not be published. Required fields are marked *