Coupang Inc. data breach: what happened and what to do
Last reviewed February 11, 2026 · 4 records on file · sources listed below
A joint public-private investigation confirmed that over 33.6 million accounts were exposed in a major data breach at Coupang's South Korean unit, significantly exceeding initial estimates of the incident's scale.
If you have an account with Coupang Inc., assume the exposed details are circulating. The practical risk today is rarely the leak itself — it is the calls and messages that use those details to sound legitimate.
What we have on file
Every entry below is a catalogued record with its original source. We do not paraphrase beyond what the source reports.
Personal Information · Unknown
South Korea's largest ever data breach compromised more than 30 million customer accounts at online retailer Coupang Inc., prompting President Lee Jae Myung to call for a swift investigation.
Personal Information · Hacking
South Korean authorities are investigating a data leak at online retailer Coupang Inc. that exposed about 33.7 million accounts, potentially making it the widest hack in the country's history. Personal information was allegedly hacked from the company's systems.
Personal Information · Vulnerability Exploitation
A massive data breach at e-commerce giant Coupang Inc. exploited the company's electronic signature key, compromising the data of over 30 million customers. The attack lasted from June to November.
What to do
- Change the password anywhere you reused itThe exposure matters most when the same password protects your email, because email is how everything else gets reset.
- Treat every call and text about this breach as a scam until proven otherwiseNo company will ask you for a one-time code, a PIN or a password. Hang up and call the number printed on your card.
- Read your statements for the next three monthsCard fraud usually starts with a small test charge. Catching that one is what stops the large one.
- Give your email account a password nothing else usesIt is the account that can reset all the others, so it is the one worth protecting first.
Questions people ask
Was my data in the Coupang Inc. breach?
Having an account alone does not confirm exposure. The reliable check is whether your email address appears in the leaked datasets in circulation — that takes seconds and does not require your password.
Is it too late to do anything?
No. Leaked personal details do not expire, and neither does the defence: a unique password on your email, and a fraud alert on your credit file, still work years later.
Will Coupang Inc. contact me?
They may. But scammers contact people too, using exactly these breach details to sound convincing. Never act on an inbound call or text — call back on a number you already had.