Close Menu
  • Home
  • Life Insurance
  • Auto Insurance
  • Home Insurance
  • Health Insurance
  • Business Insurance
  • Travel Insurance
  • Specialized Insurance
  • Insurance Tips & Guides
Facebook X (Twitter) Instagram
Insure GenZInsure GenZ Tuesday, February 10
  • About Us
  • Contact Us
  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
Facebook X (Twitter) Instagram
Subscribe
  • Home
  • Life Insurance
  • Auto Insurance
  • Home Insurance
  • Health Insurance
  • Business Insurance
  • Travel Insurance
  • Specialized Insurance
  • Insurance Tips & Guides
Insure GenZInsure GenZ
Home»Home Insurance»S. Korea Blames Coupang Data Breach on Management Failure, Not Sophisticated Attack
Home Insurance

S. Korea Blames Coupang Data Breach on Management Failure, Not Sophisticated Attack

AwaisBy AwaisFebruary 10, 2026No Comments4 Mins Read0 Views
Facebook Twitter Pinterest Telegram LinkedIn Tumblr Copy Link Email
Follow Us
Google News Flipboard
S. Korea Blames Coupang Data Breach on Management Failure, Not Sophisticated Attack
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

South Korean officials blamed a massive data leak last year at Coupang on management failure, rather than a sophisticated cyberattack, and urged the e-commerce giant to fix vulnerabilities in its security systems.

Announcing the first findings of a government-led probe, the Science Ministry said on Tuesday a former Coupang engineer, who was aware of flaws in the authentication process, broke into the system in April, a breach that lasted until November. The same person had attempted to gain access in January, it said.

Coupang Korea, operated by U.S.-listed Coupang Inc., faced a public and lawmaker backlash over the breach. The incident added to trade friction with Washington over concerns Korean authorities had gone beyond normal regulatory enforcement in their treatment of the U.S.-listed company.

“It’s more of a management problem than an advanced attack,” Choi Woo-hyuk, deputy minister for cyber security and network policy, told a press conference, citing lax oversight of authentication systems.

“The attacker exploited user authentication vulnerabilities to access user accounts without a proper login and caused large-scale unauthorized information leaks,” the ministry said.

It also called on the police to investigate Coupang for trying to “restrict” the investigation by deleting some data, accusing it of defying a government order to preserve data.

The ministry said the leak exposed personal data of about 33.7 million customers, including names and phone numbers.

Coupang said in a statement that it would “take all necessary steps to prevent further harm and continue strengthening safeguards to prevent a recurrence.”

It said a software program written by the former employee generated around 140 million queries but there was no evidence that any other party had accessed or viewed the data, which did not include payment or login information.

Coupang reiterated that data retained from around 3,000 user accounts was later deleted, adding there was no evidence any secondary harm had arisen.

‘Coupang Needs Tighter Security’

The ministry accused the former employee, who left the firm in November 2024, of stealing an internal security key, known as a signing key, which it said was used to generate fake login tokens and gain unauthorized access to customer accounts.

It said the staff member had designed and developed parts of Coupang’s user authentication system, and the company had failed to immediately invalidate the developer’s signing key after they left the company, which it said was not an adequate security system.

“Coupang needs to introduce a detection and blocking system for electronic access cards that do not go through the normal issuance process,” the ministry said.

It added that it could not comment on whether more than one person was involved in the breach and needed to wait for the results of a police investigation.

South Korean Justice Minister Jung Sung-ho said in January that an arrest warrant had been issued in December for the Chinese national who had previously worked at Coupang.

Arrest Warrant

The police investigation is ongoing and the personal data watchdog is also investigating the incident.

Coupang faces a tax audit in South Korea and a legal complaint filed by the country’s parliament against its founder and former executives after they failed to show up for parliamentary hearings last year.

The ministry accused Coupang of violating the information-network law by failing to report the breach within the required 24-hour period and it planned to impose an administrative fine of up to 30 million won ($20,596) under the law.

Coupang reported the data breach to its chief information security officer at 4:00 p.m. local time on November 17 and reported it to authorities at 9:35 p.m. on November 19, the ministry said, a period of more than 53 hours.

(Reporting by Heekyong Yang and Hyunjoo Jin, Additional reporting by Heejin Kim and Kyu-seok ShimEditing by Ed Davies, Kirsten Donovan)

Attack Blames Breach Coupang Data Failure Korea Management Sophisticated
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Telegram Email Copy Link
Awais
  • Website

Related Posts

Workers’ Compensation Insurer Beacon Mutual Dealing With Ransomware Attack

February 10, 2026

Verisk Names Kauderer President of Claims Solutions; Lang Joins CRC to Head Carrier Management

February 10, 2026

EEOC Files to Get NAPA Auto to Comply in Hiring Investigation

February 9, 2026
Leave A Reply Cancel Reply

Our Latest Blogs

Majority of Striking New York Nurses Announce Tentative Deal With Hospitals

February 10, 2026

Insurify Starts App With ChatGPT to Allow Consumers to Shop for Insurance

February 10, 2026

Talanx expects to reach 2027 earnings target a year early

February 10, 2026

Arch Capital insurance arm sees underwriting income almost quadruple

February 10, 2026
Recent Posts
  • Majority of Striking New York Nurses Announce Tentative Deal With Hospitals
  • Insurify Starts App With ChatGPT to Allow Consumers to Shop for Insurance
  • Talanx expects to reach 2027 earnings target a year early
  • Arch Capital insurance arm sees underwriting income almost quadruple
  • Musk’s Underground Vegas Tunnels Scrutinized for Safety, Environmental Concerns

Subscribe to Updates

Insure Genz is a modern insurance blog built for the next generation. Subscribe it for more updates.

Insure Genz is a modern insurance blog built for the next generation. We break down complex topics across categories like Auto, Health, Business, Life, and Travel Insurance — making them simple, useful, and easy to understand. Whether you're just getting started or looking for expert tips and guides, we've got you covered with clear, reliable content.

Our Picks

Majority of Striking New York Nurses Announce Tentative Deal With Hospitals

February 10, 2026

Insurify Starts App With ChatGPT to Allow Consumers to Shop for Insurance

February 10, 2026

Talanx expects to reach 2027 earnings target a year early

February 10, 2026

Arch Capital insurance arm sees underwriting income almost quadruple

February 10, 2026
Most Popular

Majority of Striking New York Nurses Announce Tentative Deal With Hospitals

February 10, 2026

Insurify Starts App With ChatGPT to Allow Consumers to Shop for Insurance

February 10, 2026

Talanx expects to reach 2027 earnings target a year early

February 10, 2026

Arch Capital insurance arm sees underwriting income almost quadruple

February 10, 2026
  • About Us
  • Contact Us
  • Disclaimer
  • Terms & Conditions
  • Privacy Policy
© 2026 Insure GenZ. Designed by Insure GenZ.

Type above and press Enter to search. Press Esc to cancel.