[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f10ak6ptar5cf2":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":13,"modifiedDate":14,"contentUpdatedAt":15,"source":16,"sourceUrl":17,"sourceUrls":18,"pwnCount":19,"affectedCount":19,"affectedCountStatus":20,"affectedCountLowerBound":13,"affectedCountUnit":21,"hasEnglishDescription":4,"contentLocale":22,"availableLocales":23,"translations":25,"severity":28,"dataClasses":29,"description":36,"seoTitle":37,"seoDescription":38,"logoUrl":39,"isVerified":4,"isSensitive":4,"isSpamList":40,"isMalware":40,"company":41},"6a46d43ef5a9d94368ce5f47","Coupang 2025","Coupang (2025) Data Breach","coupang-2025","coupang.com","2025-06-24T00:00:00.000Z","2026-07-02T21:12:30.362Z",null,"2026-07-03T14:23:28.069Z","2026-07-19T00:10:08.237Z","Third party breach","",[],33700000,"known","unknown","en",[22,24],"tr",{"en":26,"tr":27},{"slug":9},{"slug":9},"Critical",[30,31,32,33,34,35],"Email addresses","Names","Phone numbers","Physical addresses","Purchases","Purchase histories","\u003Cp>The Coupang data breach is a critical customer data incident investigated within the framework of the South Korea-based e-commerce and fast delivery platform associated with the domain coupang.com, which began in June 2025 and was announced at the end of November 2025. The record was added as a singular incident supported by 33,700,000 customer accounts. The record contained email addresses, names, phone numbers, physical addresses, purchase information, and order history; unsupported claims of passwords, payment cards, bank accounts, or full account access were excluded so as not to mislead the user.\u003C\u002Fp>\u003Ch2>Leaked Data Types and Risks\u003C\u002Fh2>\u003Cp>In the verification assessment, the name Coupang, the domain coupang.com, the context of South Korean e-commerce, the start of access in June 2025, the disclosure in November 2025, and the scale of 33.7 million customer accounts were considered together. While customer contact information and order history fields were supported in the incident, payment and login information were not supported and therefore were not added to the record. This approach was chosen to accurately convey the magnitude of the incident while not misleading the user with unsupported data types.\u003C\u002Fp>\u003Ch2>Verified Scope and Boundaries\u003C\u002Fh2>\u003Cp>The Coupang data breach creates risks for users such as delivery fraud, fake order notifications, return requests, campaign messages, and targeted phishing. When name, phone, email, address, and order history are combined, attackers can prepare messages that appear like a real delivery or shopping transaction. A link may be sent to the user under the pretext of missing address, delivery fee, product return, fake customer service, account verification, or coupon campaign. Therefore, even if the incident does not contain passwords, the practical fraud risk is high.\u003C\u002Fp>\u003Ch2>User Groups at Risk\u003C\u002Fh2>\u003Cp>In this case, the visible data classes are sensitive because they combine with the context of e-commerce and logistics. Physical address and phone number make it easy to reach the user directly. Order history or purchase information makes the message appear as if it is associated with a real purchase. Email and name fields personalize phishing messages. It has not been extended as if there were a registered payment card or account password; however, the existing fields still provide a strong context for delivery, return, and customer support fraud.\u003C\u002Fp>\u003Ch2>Urgent Measures to Be Taken\u003C\u002Fh2>\u003Cp>Users with a Coupang account should directly check unexpected delivery, return, address correction, payment difference, coupon, or account verification messages through the known official channel. One-time codes, payment information, or account login requests received by phone should not be shared. Multi-factor authentication should be enabled on email accounts, and unique passwords should be used for shopping accounts. Messages containing real order or address information should not be automatically assumed to be trustworthy.\u003C\u002Fp>\u003Ch2>Long-Term Security Strategies\u003C\u002Fh2>\u003Cp>From the perspective of institutions, the Coupang data breach shows the fraud value of customer data on e-commerce and fast delivery platforms. Support teams should not approve transactions with only a name, phone number, address, or order information. Additional verification is required for actions such as address changes, returns, payment redirection, account recovery, and delivery requests. E-commerce business partners and shipping processes should also be alerted against fake orders and delivery messages. Users should be clearly informed about official message formats and false link reporting.\u003C\u002Fp>\u003Cp>The scope of the Coupang data breach record was limited to supported areas. The record was kept as 33,700,000 customer accounts; claims of payment card, bank account, password, or full account access were not included. The data classes are limited to customer communication, address, and purchase\u002Forder context. Nevertheless, the incident poses a critical risk because it is very large in volume and combines order history with address fields. Users should be particularly cautious of fake messages containing personal order information.\u003C\u002Fp>\u003Ch2>Record Control and User Action\u003C\u002Fh2>\u003Cp>The overall risk level has been assessed as critical because the Coupang data breach combines large-scale e-commerce customer data with addresses, phone numbers, and order history. The most practical steps for users searching for Coupang data breaches are to independently verify delivery and return links, not trust codes sent via phone, enable additional verification on email and shopping accounts, avoid reusing the same password, and carefully examine messages prepared with personal order information. The record has been prepared to explain the actual impact on customer security without including unsupported payment or account access claims.\u003C\u002Fp>","Coupang (2025) Data Breach (33.7 Million Reported Records)","Coupang (2025) Data Breach. 33.7 Million reported records are reported. Reported data: Email addresses, Names, Phone numbers. Review the scope, risks, and…","\u002Fuploads\u002Flogo\u002Fcoupang-2025.svg",false,{"name":42,"sector":43,"country":44,"website":10,"websiteArchiveUrl":17,"websiteStatus":17,"websiteCheckedAt":13},"Coupang","E-commerce \u002F Delivery platform","South Korea"]