Coupang data breach: what happened and what to do
Last reviewed July 18, 2026 · 9 records on file · sources listed below
Coupang, a major e-commerce firm, was fined by South Korea over a data leak that has caused diplomatic tensions between the US and South Korea.
If you have an account with Coupang, assume the exposed details are circulating. The practical risk today is rarely the leak itself — it is the calls and messages that use those details to sound legitimate.
What we have on file
Every entry below is a catalogued record with its original source. We do not paraphrase beyond what the source reports.
Personal Information · Unknown
Coupang suffered a data breach that exposed private data. The incident has raised regulatory concerns in South Korea regarding the handling of such events.
Personal Information · Vulnerability Exploitation
South Korean authorities announced that e-commerce giant Coupang experienced a massive data leak caused by vulnerabilities in its security systems. The investigation found security loopholes that led to the data breach.
Personal Information · Unknown
Coupang, a South Korean e-commerce company, experienced a consumer data breach that has led to legal actions by U.S. investors who accuse the South Korean government of discriminatory treatment following the incident.
Personal Information · Unknown
A data breach at Coupang resulted in compromised sensitive data, leading to a securities fraud class action lawsuit due to subsequent stock decline. Investors have until February 17, 2026 to file claims related to the breach.
Personal Information · Unknown
Coupang CEO resigned following a historic data breach in South Korea that affected nearly two-thirds of the country's population. The breach granted unauthorized access to shipping addresses and phone numbers.
Personal Information · Unknown
South Korean President Lee Jae Myung addressed a massive customer data leak from e-commerce platform Coupang. The breach went undetected by the company for five months, prompting calls for stronger digital privacy protections and tougher penalties for such incidents.
Personal Information · Unknown
The CEO of South Korean online retail giant Coupang resigned following a massive data breach that affected nearly 34 million customers. The breach was revealed on November 18, 2025.
Personal Information · Unknown
South Korean police are investigating a massive data breach at e-commerce giant Coupang, where personal data of more than 33 million customers was leaked. The breach is believed to have started on June 24 through overseas servers, though the company did not learn of the problem until November 18. This is described as the country's worst data breach in over a decade.
What to do
- Change the password anywhere you reused itThe exposure matters most when the same password protects your email, because email is how everything else gets reset.
- Treat every call and text about this breach as a scam until proven otherwiseNo company will ask you for a one-time code, a PIN or a password. Hang up and call the number printed on your card.
- Read your statements for the next three monthsCard fraud usually starts with a small test charge. Catching that one is what stops the large one.
- Give your email account a password nothing else usesIt is the account that can reset all the others, so it is the one worth protecting first.
Questions people ask
Was my data in the Coupang breach?
Having an account alone does not confirm exposure. The reliable check is whether your email address appears in the leaked datasets in circulation — that takes seconds and does not require your password.
Is it too late to do anything?
No. Leaked personal details do not expire, and neither does the defence: a unique password on your email, and a fraud alert on your credit file, still work years later.
Will Coupang contact me?
They may. But scammers contact people too, using exactly these breach details to sound convincing. Never act on an inbound call or text — call back on a number you already had.
701 organisations catalogued
Records are catalogued from public reporting and linked to their original source. iTellYou is not affiliated with the organisations listed. If you represent one of them and something here is inaccurate, write to us and we will correct it.