South Korea’s largest online retailer, Coupang, announced on December 1, 2025, a massive data breach that may have compromised as many as 34million local customer accounts, nearly two-thirds of South Korea’s population. The e-commerce platform is viewed as South Korea’s equivalent of Amazon.com.
The breach marks the most recent in a string of data leaks affecting major companies in the country, among them the telecommunications giant SK Telecom. It has sparked a diplomatic “flashpoint” between the US and South Korea. US investors and lawmakers have expressed concerns that Coupang, a US-listed firm, may be facing discriminatory regulatory actions in South Korea compared to domestic companies.
Key details of the incident
Unauthorized access is believed to have begun on June 24, 2025, but was not identified by the company until Nov 18, 2025.
In February 2026, Coupang confirmed an additional 165,000 accounts were compromised via leaked address book information. Compromised information includes customer names, phone numbers, email addresses, shipping addresses, and order histories.
Coupang has repeatedly stated that payment details (credit card numbers) and login credentials (passwords) were not accessed.
Reported investigation findings
Investigations point to a former employee, a 43-year-old Chinese national who previously worked in authentication management. The individual allegedly used an active authentication key after their contract was terminated to gain access.
The suspect is believed to be in China. South Korean authorities have obtained an arrest warrant and are working with Interpol to seek repatriation.
In December 2025, Seoul police conducted a “search and seizure” operation at Coupang’s South Korean headquarters. Interim CEO Harold Rogers has been summoned for questioning regarding possible evidence tampering and negligence.
Legal ramifications
Coupang has pledged USD1.18billion (approx. 1.7 trillion won) in compensation, primarily in the form of shopping vouchers worth up to 50,000 won ($35) per affected customer. The move faced criticism because the compensation was tied to future spending on Coupang’s platforms, including Coupang Eats, Travel, and their luxury beauty service, R.LUX.
Over 240,000 victims have filed a collective lawsuit in South Korea. Additionally, a US class-action lawsuit has been filed in New York, alleging gross mismanagement of security protocols by the US-based parent company.
Coupang Corp. CEO Park Dae-jun resigned in Dec 2025 following the initial disclosure.
Flashpoint in US-South Korea relations
In late January 2026, US President Donald Trump announced an increase in tariffs on South Korean goods from 15% to 25%.
South Korean National Security Adviser Wi Sung-lac stated that this tariff decision was directly “linked” to the Coupang matter and broader US dissatisfaction with South Korean digital regulations.
US pushback
US lawmakers and investors have criticized South Korea’s response as disproportionate. Authorities reportedly deployed 400 investigators from 11 different agencies, which US critics describe as an attempt to “bankrupt” an American competitor.
Major US investors, including Greenoaks Capital and Altimeter Capital, filed arbitration claims under the US-Korea Free Trade Agreement (KORUS). They allege that the investigation has wiped out billions in market value and that Coupang is being treated more harshly than Korean domestic firms involved in similar past breaches.
Kevin Warsh, President Trump’s nominee for Federal Reserve Chair, has served on Coupang’s board of directors since 2019. Critics argue that having a potential Fed Chair tied to a company under active criminal investigation in an allied nation creates a massive conflict of interest.
Domestic reactions
In South Korea, the US pushback is viewed by some as an interference in domestic affairs and a violation of national sovereignty.
The dispute highlights a core tension: Coupang is legally an American company (registered in Delaware) but operates almost exclusively in South Korea, where the public demands local accountability that the US sees as “unfair targeting”.
South Korean officials, including National Security Adviser Wi Sung-lac, have expressed that the US is using the Coupang matter to pressure Seoul into walking back digital platform regulations that would affect other US tech giants.
In South Korea, the perception that a “US political shield” is being used to bypass local consumer protection laws has fueled public anger and further radicalized the legal response against the company.
South Korea’s wave of data breaches in 2025
In 2025, South Korea experienced a “near-monthly” wave of major data breaches that systematically compromised the nation’s digital backbone, affecting telecommunications, finance, e-commerce, and the military.
This surge has led experts to label 2025 as the “worst year for security” in the country’s history. All three major providers (SK Telecom, KT, and LG Uplus) suffered compromises in 2025, highlighting systemic risks in the country’s mobile-based authentication systems.
The South Korean military reported over 9,200 hacking attempts in the first half of 2025 alone, a 45% increase from the previous year. North Korea-linked group Kimsuky escalated tactics by using AI-generated deepfakes in spear-phishing campaigns against defense-related institutions in July.
The Coupang incident emphasized a major regulatory blind spot: the exploitation of retained permissions by former employees.
The Personal Information Protection Commission (PIPC) has shifted to a “proactive inspection” model, imposing record-breaking fines and conducting sector-wide probes into “super apps” like KakaoTalk and Naver to address persistent failures in cybersecurity controls.
Read also:
Trump nominates Kevin Warsh as next Fed chair
US-South Korea Trade Spat revives tariff talk











