Background and Timeline: On February 6, 2026, South Korean e-commerce giant Coupang disclosed a data leak linked to an incident first identified in November 2025. The announcement came after recommendations from the state personal information protection watchdog. Coupang has been under intense scrutiny regarding the initial breach, with authorities disputing the company’s early claims about the minimal impact.
Modus Operandi: The breach was the result of a failure in Coupang’s internal data controls and shipping management systems. This allowed for the unauthorized exposure of customer shipping lists, which contained names, phone numbers, and home addresses entered by users. The leaked data was not protected by adequate access monitoring, allowing it to be accessed over a sustained period before the lapse was contained.
Victims and Financial Impact: 165,000 accounts were confirmed leaked in this specific disclosure, though Korean authorities suspect the actual number could reach 33 million. This represents a significant portion of South Korea’s population, making it one of the largest potential leaks in the nation’s history. While no passwords or credit card details were reportedly stolen, the PII leak poses a massive identity theft risk.
Investigation and Agencies Involved: Korean police and personal information protection watchdogs are currently investigating the reliability of Coupang’s internal probe, which they criticized as “one-sided”. The investigation is focusing on whether the company deliberately attempted to downplay the scale of the compromise. Authorities are analyzing whether any external threat actors have already begun monetizing the leaked dataset.
Arrests and Suspects: Harold Rogers, the interim CEO of Coupang, recently underwent 12 hours of police questioning regarding allegations of destroying evidence linked to the massive breach. He also faces accusations of obstructing official investigations into the initial November incident. No formal charges have been filed yet, but the executive questioning signals a move toward holding corporate leadership directly accountable.
Broader Implications and Trends: The Coupang case highlights a growing global trend where regulators are no longer accepting “minimalist” breach disclosures from tech giants. Corporate accountability for data breaches is being strictly enforced, including potential criminal charges for obstruction or lack of transparency. This incident reflects a phase where multiple risks—regulatory, technical, and reputational—converge.