Skip to content
cisonews.net

Incident · 8-K Item 1.05

Coupang reports access to up to 33 million customer accounts at its Korean subsidiary

Compiled 2026-09-27 from public records. By the cisonews.net Desk.

Coupang, the South Korean e-commerce company listed in New York, disclosed on December 16, 2025 that its Korean operating subsidiary had become aware on November 18 of unauthorized access to customer accounts. It said a former employee, whom the filing does not name, may have obtained contact and delivery details linked to up to 33 million accounts.

Original filing

Coupang listed the data as names, phone numbers, delivery addresses and email addresses, plus some order histories, and said no banking, payment card or login credentials were obtained. Korean regulators had opened investigations, and Coupang said penalties were possible but could not be estimated.

December 29 amendment

The 8-K/A reported that while about 33 million accounts were accessed, only limited data from roughly 3,000 accounts had been saved, and that data had been deleted without being shared. It also announced a customer compensation program.

Scope of this entry

This entry records the company's disclosures. It does not identify the former employee, and the filings do not either.

Sources

  1. 2025-12-16 · ACoupang, Inc., Form 8-K (SEC EDGAR), published December 16, 2025
  2. 2025-12-29 · ACoupang, Inc., Form 8-K/A (SEC EDGAR), published December 29, 2025

Tier A: the organization itself, a regulator or SEC EDGAR. Tier B: established press. Each fact on this page carries its supporting passage in the page source.

See an error? Corrections are made on the page and logged on the corrections page. Send them through contact.