By NHI Mgmt Group Editorial TeamDomain: Cyber SecuritySource: NightfallPublished December 23, 2025

TL;DR: The Coupang breach likely exposed nearly 34 million customer records over months, showing how unauthorized data access can persist while passwords and payment data remain secure, according to Nightfall’s analysis. The lesson is that data-layer visibility and exfiltration controls, not just IAM and endpoint monitoring, determine whether exposure stays contained or becomes a regulatory and trust event.


At a glance

What this is: This is Nightfall's analysis of the Coupang breach, arguing that prolonged unauthorized access to customer data exposed a data-layer visibility gap rather than a perimeter failure.

Why it matters: It matters because IAM, endpoint, and firewall controls can still miss slow data exfiltration, forcing identity and security teams to govern access, movement, and response at the data layer.

By the numbers:

👉 Read Nightfall's analysis of the Coupang breach and data-layer exposure


Context

Coupang's breach is a data governance problem as much as a security incident. Sensitive customer information can remain exposed for months when organisations do not continuously monitor how data is accessed, moved, and exported across backend systems, cloud services, and internal tools. In identity terms, the failure is not only who had access, but whether data use stayed within the intended boundary.

For practitioners, this is a reminder that infrastructure controls do not provide complete coverage once attackers or insiders reach the data plane. The case is typical of modern large-scale breaches: quiet, persistent, and visible only after exposure has already expanded.

Traditional security models often optimise for systems and accounts, yet the business impact comes from data movement and misuse. The important question is whether security teams can see abnormal access early enough to interrupt it before customer trust and regulatory exposure accumulate.


Key questions

Q: What fails when organisations rely on IAM alone for customer data security?

A: IAM can confirm that an account authenticated, but it cannot show whether the account used data in approved ways. When sensitive records move through databases, SaaS tools, and exports, the real failure is data-plane blindness. Organisations need discovery, behavioural monitoring, and exfiltration controls to see whether access has turned into unauthorized transfer or prolonged exposure.

Q: Why do slow data breaches stay hidden for so long?

A: Slow breaches blend into normal operational activity because queries, exports, and synchronisation jobs can look legitimate unless teams watch for volume, destination, and timing changes. If monitoring stops at the identity layer, prolonged access can continue unnoticed. Detection needs to focus on data movement signals, not only login or endpoint events.

Q: How do security teams know if exfiltration controls are actually working?

A: Look for evidence that bulk file access, compression, and outbound staging are detected early and correlated with privileged sessions. If teams only see the breach after a leak site post, the control failed. Effective monitoring should surface unusual data movement before attackers can weaponise it.

Q: Who is accountable when customer data is exposed for months?

A: Accountability usually spans security operations, data owners, legal, privacy, and executive risk management because prolonged exposure is both a control failure and a governance issue. Regulators will ask whether baseline protection obligations were met, whether monitoring was continuous, and whether the organisation could prove timely containment.


Technical breakdown

Why data discovery is the first control failure

Sensitive data cannot be protected consistently if teams do not know where it lives. In large environments, customer records are spread across production databases, SaaS tools, cloud storage, collaboration platforms, and third-party workflows. Data discovery and classification replace assumptions with inventory, then classify what is sensitive enough to require tighter controls. Without that visibility, access reviews and policy enforcement are always lagging behind reality, because the control set is built on an incomplete map of the estate.

Practical implication: establish continuous discovery for all customer-data repositories before relying on access policy or response logic.

How prolonged access turns into data exfiltration

Most long-running breaches do not depend on a single dramatic event. They often look like ordinary queries, exports, or synchronisation jobs until volume, timing, or destination changes reveal abuse. Data detection and response focuses on those behavioural deviations, using thresholds and patterns to identify when access no longer matches normal workflows. This matters because valid credentials can still be used for malicious transfer, so account-level monitoring alone will not surface the breach early enough.

Practical implication: monitor query volume, export activity, and transfer destinations as first-class security signals, not just login events.

Why exfiltration prevention changes the blast radius

Exfiltration prevention applies policy at the point data leaves approved environments. That is different from stopping access, because the credential may be valid and the user may appear legitimate. The control objective is to prevent sensitive records from being copied, shared, or moved outside defined boundaries when the access pattern becomes risky. In practice, this is the layer that limits impact when detection is late or when an insider or compromised account already has read access.

Practical implication: enforce policy-based blocking for high-risk exports and cross-environment transfers, especially for customer and order data.


Threat narrative

Attacker objective: The likely objective was prolonged access to customer information at scale for downstream misuse, resale, or exploitation.

  1. Entry occurred through sustained unauthorised access to backend systems that held customer data, rather than through a noisy perimeter event.
  2. Credentialed access was abused over time to query or move sensitive records without triggering timely interruption.
  3. Impact expanded as nearly 34 million records were likely exposed, increasing the risk of phishing, fraud, regulatory scrutiny, and trust loss.

NHI Mgmt Group analysis

Data-layer blindness is now a breach amplifier: When organisations can see identities and infrastructure but not data movement, they lose the ability to distinguish authorised access from harmful extraction. This breach shows that the decisive failure is not only detection latency, but the absence of continuous visibility into how sensitive records are used. Practitioners should treat data-plane observability as a core control, not an optional enhancement.

Continuous data oversight is the missing governance layer: Traditional IAM can confirm who authenticated, but it cannot by itself prove that customer data remained inside approved use cases. That is why breaches like this expose a governance gap between entitlement and actual data handling. For identity and security teams, the control question becomes whether access, export, and transfer can all be monitored as a single policy surface.

Blast-radius reduction must reach the data itself: Exfiltration prevention matters because the breach cost is driven by what can be copied, not only by what can be entered. The named concept here is data-plane exposure drift, where sensitive data gradually becomes reachable outside intended oversight and the organisation notices only after volume has accumulated. The practical conclusion is that policy must follow the data wherever it moves.

What this signals

Data-plane exposure drift: this breach pattern shows how sensitive records can move outside intended oversight long before infrastructure alarms fire. For identity and data security teams, the operational shift is to treat export activity, query behaviour, and transfer destinations as core control signals, then align them with NIST AI Risk Management Framework style governance even when the immediate problem is not AI.

The practical programme change is to bring data discovery, behavioural detection, and response into one operating model. That approach is especially relevant where personal data flows across cloud and SaaS environments, because broad access is no longer the issue; uncontrolled data motion is.

If your environment already struggles to map who can see sensitive data, the next failure will usually be proving whether that data stayed inside approved uses. The right response is to instrument the data path before you need the breach narrative to explain it.


For practitioners

  • Implement continuous data discovery Map customer data across databases, SaaS platforms, cloud storage, and internal tools so security controls are based on current location rather than assumptions.
  • Monitor data access behaviour continuously Alert on unusual query volumes, unexpected exports, and transfers that do not match normal business workflows, especially for high-value customer datasets.
  • Enforce exfiltration prevention on sensitive records Block or quarantine high-risk copies of personal information when data leaves approved environments, even if the access credential itself appears valid.
  • Reassess incident response for slow-burn exposure Add playbooks that treat prolonged unauthorised access as a live containment problem, with data-owner and legal escalation built in.

Key takeaways

  • Coupang's breach illustrates a prolonged data-layer failure, not a simple perimeter break.
  • Nearly 34 million records likely sat exposed long enough to create privacy, fraud, and trust consequences beyond the initial access event.
  • Continuous discovery, behavioural monitoring, and exfiltration prevention are the controls that shorten exposure windows when IAM alone cannot.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK address the attack surface, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the technical controls, and ISO/IEC 27001:2022 define the regulatory obligations.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0DE.CM-1Continuous monitoring of data movement is central to this breach pattern.
NIST SP 800-53 Rev 5SI-4Monitoring and analysis of data access events fits this breach profile.
CIS Controls v8CIS-13 , Network Monitoring and DefenseMonitoring is needed where data leaves expected environments.
ISO/IEC 27001:2022A.8.12Data leakage prevention is directly relevant to the exposure pattern described.
MITRE ATT&CKTA0010 , ExfiltrationThe article centres on prolonged data theft and transfer rather than initial intrusion.

Instrument data access and transfer activity so abnormal movement is detected before exposure expands.


Key terms

  • Data Discovery: Data discovery is the process of finding where information lives across cloud, SaaS, endpoints, backups, and analytics systems. In practice, it creates the inventory that makes classification, access decisions, recovery planning, and AI governance possible rather than speculative.
  • Data Exfiltration Prevention: Data exfiltration prevention is the control layer that blocks or restricts sensitive information from leaving approved environments. It focuses on stopping unauthorized copying, exporting, or sharing even when the account or session appears valid, making it a key containment measure when detection is delayed.
  • AI Detection and Response: The runtime layer that watches agent behaviour as actions unfold and intervenes when patterns deviate from policy or intent. It focuses on live action chains, anomalous tool use, and behavioural drift, giving teams a way to stop misuse that configuration review would never see in isolation.

What's in the full article

Nightfall's full report covers the operational detail this post intentionally leaves for the source:

  • A closer breakdown of how data discovery, detection, and exfiltration prevention work together in Nightfall's operating model.
  • Product-specific examples of policy-based controls for data leaving approved environments, including how alerting thresholds are defined.
  • The report's broader State of Agentic Data Security 2026 context, which links this breach pattern to emerging AI-driven data exposure risks.
  • Implementation-oriented guidance on where sensitive data tends to hide across cloud, SaaS, and internal workflows.

👉 Nightfall's full post covers the breach timeline, data controls, and response considerations in more detail.

Deepen your knowledge

The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps security practitioners connect identity controls to the broader risk picture their programmes must govern.
NHIMG Editorial Note
Published by the NHIMG editorial team on August 20, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org