Desk live·
ForensicPost
Breaches/Retail/File 25-1130

Coupang Breach Affected 33.7 Million Customer Accounts

Coupang reported a breach affecting 33.7 million customer accounts. In a national market, a single platform breach approaches the population.

Constructed geometry · not a chart of case data
TargetCoupang
ActorUnattributed
D. Kennedy11 min readConfidence: high2 sources reviewed

The South Korean e-commerce platform Coupang reported a data breach compromising 33.7 million customer accounts, exposing names, email addresses, telephone numbers, shipping addresses and certain order histories.

National Platforms Produce Population-Scale Breaches

South Korea’s population is around 52 million. A single platform’s affected account count reaching 33.7 million is not a large breach at a large company — it is most of a country.

The corpus filed the same structure at 25-0501, where all 6.5 million Co-op members were taken, and at 25-0909, where two of four French carriers disclosed within a month. Where a market has one dominant platform, the distinction between a company’s customer list and a national register largely disappears.

Order History Is The Field That Keeps Being Underrated

Names and addresses are the fields that trigger notification. Order history is the field that describes a person: what they buy, how often, for whom, and what changed when.

On a platform that sells groceries, medicines, baby products and household goods, a purchase record is a household inventory over time. This desk made the same argument about a luxury customer list at 25-0603 and about utility consumption at 26-0326 — the sensitivity is in the inference, and no data-protection assessment has a column for it.

And It Is A Rare Non-Western File With A Firm Number

The corpus documented at 25-0502 that incidents outside a handful of jurisdictions rarely produce affected counts. South Korea has a mandatory disclosure regime and an active regulator, which is why this file has a figure at all.

That is the argument at 25-1221 in a single case: the countries that appear worst in breach statistics are frequently the ones that measure.

How we reported this

Compiled from public reporting, listed below. The intrusion route is not established in the material we reviewed. Corrections: corrections@forensicpost.com.

Sources
  1. Top data breaches in 2025, month-wiseSecurity Boulevard
  2. The biggest cybersecurity and cyberattack stories of 2025BleepingComputer
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary