Between April and November 2025, a former Coupang engineer used an authentication signing key he had taken while employed to pull personal data on about 33.7 million accounts from South Korea's largest online retailer. According to the joint government investigation, the key was never revoked or rotated after he left, and Coupang's systems did not check whether the access tokens made with it were genuine. The attacker forged what investigators called an "electronic access badge" and ran automated queries against customer pages for months, generating around 140 million requests. Names, email addresses, phone numbers, delivery addresses and, for some users, building entrance codes and order histories were exposed. Coupang disclosed the full scale on 29 November 2025, and in June 2026 the Personal Information Protection Commission (PIPC) imposed a record fine. The Coupang breach is a clear case of a non-human credential, a token signing key, outliving the human who held it.
Key takeaways
- The attacker was a former developer on Coupang's user authentication system who left the company at the end of 2024 and kept a signing key he had obtained while employed.
- Government investigators found the key was not revoked or rotated after he left, keys were stored on developer laptops, and forged tokens were not verified. A lawmaker said Coupang's signing keys had validity periods of 5 to 10 years.
- Main data harvesting ran from April to November 2025, after a test run in January 2025, using more than 2,300 IP addresses and around 140 million automated queries.
- The government put exposed records at 33.67 million; the PIPC later counted 33.2 million members plus 4.3 million non-member delivery recipients. Coupang says the attacker retained data from only about 3,000 accounts.
- Lesson: signing keys are high-value non-human identities. They need an owner, a short lifetime, secure storage and revocation as part of every leaver process.
At a glance
| Organisation | Coupang (Coupang Corp in South Korea; parent Coupang, Inc.) |
|---|---|
| When | Test access January 2025; data harvesting April to November 2025; detected 17 to 18 November 2025; full scale disclosed 29 November 2025; PIPC fine 11 June 2026 |
| Attacker | A former Coupang developer, a Chinese national, who had worked on the user authentication system; subject of a Korean arrest warrant and an Interpol red notice |
| Entry point | Coupang's customer-facing web and app services, reached with access tokens forged using a stolen signing key |
| Identities abused | An authentication token signing key that was never revoked or rotated after the developer left; forged customer access tokens; the departed employee's retained access to key material |
| Impact | 33.67 million user records exposed according to the government investigation; 37.5 million people counted by the PIPC including non-members; record 624.7 billion won PIPC fine |
| Category | NHI (signing key and forged tokens), with an insider and offboarding failure as the human element |
What happened
Coupang first reported unauthorised access to about 4,500 accounts. According to Reuters, citing the government investigation, the incident was reported to Coupang's chief information security officer at 4pm on 17 November 2025, and to the authorities at 9:35pm on 19 November, more than 53 hours later, against a 24-hour legal requirement. On 29 November Coupang said the exposure in fact covered about 33.7 million accounts. CSO Online reported that the exposed data included names, email addresses, shipping address lists and some order information, but not payment data, card numbers or login credentials.
Suspicion quickly fell on a former engineer. CSO Online reported that the token signing keys involved had validity periods of "5 to 10 years", and quoted lawmaker Choi Min-hee saying Coupang "did not follow the most basic internal security procedure of renewing the signing key." South Korean prosecutors obtained an arrest warrant for the Chinese former employee on 8 December 2025 and asked Interpol for a red notice, the Korea JoongAng Daily reported.
On 25 December 2025 Coupang published the results of its own forensic investigation. It said the former employee had confessed and used "a stolen internal security key" to access basic data on 33 million accounts, but had retained data from only about 3,000 of them and later deleted it. Coupang said he had thrown his MacBook Air into a river inside a Coupang bag weighted with bricks, and that the device was recovered and handed to the government.
The joint public-private investigation team, led by the Ministry of Science and ICT, published its findings on 10 February 2026. The Korea Herald reported that the attacker "was a former developer who had worked on Coupang's user authentication system", that he "obtained a signing key" while employed, and that the key "was later used to forge what investigators referred to as an 'electronic access badge.'" Investigators said forged credentials were not verified, signing keys held by departed employees were never revoked or rotated, and keys were kept on developer computers. Choi Woo-hyuk of the Ministry of Science and ICT told Reuters: "It's more of a management problem than an advanced attack."
The government also found that Coupang deleted access logs despite a preservation order. The Record reported that the PIPC later found about six months of logs had been deleted manually and about 13% of the logs covering the attack period were lost. The government said it would fine Coupang for late reporting and referred the log deletion for investigation.
Coupang disputed parts of the findings. In its response to the investigation report, it said "all forensic evidence is consistent with his statement that he retained data from approximately 3,000 user accounts, and later deleted all of it", and that it had found no secondary harm. On 11 June 2026 the PIPC fined Coupang 624.7 billion won, which The Record said surpassed the previous record fine against SK Telecom. Coupang said it regretted the decision and reserved the right to challenge it.
Timeline
| Date | Event |
|---|---|
| End of 2024 | The developer leaves Coupang, retaining a signing key he obtained while employed (PIPC, via The Record). |
| January 2025 | Test run against 95 accounts using forged tokens (PIPC, via The Record). |
| 14 April 2025 | Systematic unauthorised access begins, according to KEIA's timeline of the government findings; it continues until 8 November 2025. |
| 17 November 2025 | Incident reported to Coupang's CISO; Coupang initially identifies about 4,500 affected accounts. |
| 19 November 2025 | Coupang reports to the authorities at 9:35pm, more than 53 hours after discovery. |
| 29 November 2025 | Coupang discloses that about 33.7 million accounts were exposed; a joint investigation team is formed the next day. |
| 8 December 2025 | Court issues an arrest warrant for the former employee; an Interpol red notice follows. |
| 25 December 2025 | Coupang publishes its forensic findings: data retained from about 3,000 accounts, laptop recovered from a river. |
| 10 February 2026 | Government investigation confirms 33.67 million records and blames signing key management failures. |
| 11 June 2026 | PIPC fines Coupang a record 624.7 billion won in total, citing deficiencies in basic safety management. |
How it happened: the identity attack path
- A signing key in a person's hands. The developer worked on Coupang's authentication system and obtained a token signing key. Investigators found signing keys were kept on developer computers.
- Offboarding that missed the machine credential. He left the company at the end of 2024. His staff account could be switched off, but the signing key he knew was not revoked or rotated, so it stayed valid long after he had gone.
- Forging trusted tokens. With the key, he could mint authentication tokens that Coupang's services accepted as genuine. Investigators said there was no process to verify whether tokens were forged.
- Testing, then scaling. After a small test run in January 2025, he wrote his own query software and harvested data from April 2025, using more than 2,300 IP addresses and around 140 million automated requests to delivery address, order history and account pages.
- Months without detection. The Korea Herald reported that the delivery address list was accessed more than 148 million times, yet the activity ran for about seven months before Coupang detected it in November 2025.
- Weakened evidence. Deleted logs meant part of the attack period could not be reconstructed, which is one reason Coupang and regulators still disagree on how much data was taken.
Impact
- Scale: the government put exposed records at 33.67 million, plus 165,455 accounts affected separately. The PIPC counted 33,222,472 registered members and 4,338,368 non-member delivery recipients, according to The Record.
- Data: names, email addresses, phone numbers and delivery addresses; for some users, order histories and building entrance codes. Coupang says entrance codes were accessed for 2,609 accounts and that no payment data, passwords or government IDs were accessed.
- Disputed volume: Coupang maintains the attacker retained data from about 3,000 accounts and deleted it, and that no dark web activity or secondary harm was found. Regulators base their figures on access to the data rather than on what the attacker kept.
- Financial: Coupang announced 1.685 trillion won in purchase vouchers, 50,000 won per account. The PIPC fine totalled 624.7 billion won, which The Record said included 201.1 billion won for separate covert collection of browsing data.
What this means for NHI governance
The Coupang breach began with a person, but the credential that did the damage was not a password or a staff account. It was a signing key, the root of trust behind every customer session token Coupang issued. Whoever holds such a key does not need to log in as anyone. They can create identities the system will believe. That makes a token signing key one of the most powerful non-human identities an organisation owns, and one of the least visible.
Three governance failures stand out in the official findings. First, custody: the key was on developer machines instead of being confined to a managed store. Second, lifecycle: a key with a multi-year validity period was never rotated, and nothing in the leaver process tied the developer's departure to the keys he could have copied. Third, verification: forged tokens were accepted without checks that could have flagged tokens the legitimate issuer never created. Any one of these controls would have narrowed the window; together their absence gave a former insider seven months of access.
This is the joiner-mover-leaver problem applied to machines. Most organisations disable a departing engineer's accounts promptly. Far fewer ask which secrets, keys and certificates that engineer could see, and rotate them. When long-lived keys are shared, stored locally and without a named owner, the only safe assumption at offboarding is that they have left the building too.
Recommendations
- Tie offboarding to credential rotation. When someone with access to keys, secrets or certificates leaves or changes role, rotate what they could reach. Our Joiner-Mover-Leaver (JML) Guide covers how to build this into the leaver process.
- Keep signing keys in an HSM or managed key service. Developers should be able to use a key through the service, never export it to a laptop.
- Give signing keys short lives and a rotation schedule. Multi-year keys turn one theft into years of exposure. The Machine Identity, PKI and Certificate Lifecycle Guide sets out rotation and revocation practices.
- Assign an owner to every high-value NHI. Inventory signing keys, record who can access them and review that access, as described in our NHI lifecycle management guide.
- Make forged tokens detectable. Check that tokens map to real issuance events and sessions, and alert when valid-looking tokens appear without a matching login.
- Watch for bulk access patterns. Hundreds of millions of requests to address and order pages from thousands of IP addresses should trigger rate limits and investigation well before seven months pass.
- Protect logs as evidence. Keep access logs in tamper-resistant storage with retention that cannot be overridden manually during an incident.
Frequently asked questions
What happened in the Coupang data breach?
A former Coupang developer used a token signing key he had obtained while employed to forge access tokens and query customer data from April to November 2025. The government said 33.67 million user records were exposed, including names, emails, phone numbers and delivery addresses.
How did the Coupang hacker get access after leaving the company?
The signing key was never revoked or rotated after he left at the end of 2024, and Coupang's systems did not verify whether tokens were forged. Investigators also found signing keys were stored on developer computers.
Were Coupang payment details or passwords leaked?
Coupang and the press reports say no payment data, card numbers, passwords or login credentials were accessed. Building entrance codes and some order histories were exposed for a subset of users.
Related NHI Mgmt Group resources
Coinbase insider breach 2025 · Home Depot year-long token exposure · Joiner-Mover-Leaver (JML) Guide · Machine Identity, PKI and Certificate Lifecycle Guide · Secrets Management Guide
How NHI Mgmt Group can help
Coupang shows that offboarding a person is not complete until the keys and secrets they could reach are rotated. Our NHI Foundation Level Training Course teaches teams how to inventory, own and rotate signing keys and other non-human identities across their lifecycle.
References
- Coupang, Inc.: Update on Coupang Korea Cybersecurity Incident (25 December 2025, updated 29 December 2025)
- Coupang, Inc.: Response to the JIT Report regarding the November 2025 data incident (10 February 2026)
- The Korea Herald: Gov't calls Coupang breach of 33.7m records worst ever (10 February 2026)
- Reuters via Claims Journal: South Korea Blames Coupang Data Breach on Management Failure, Not Sophisticated Attack (11 February 2026)
- CSO Online: Coupang breach of 33.7 million accounts allegedly involved engineer insider (4 December 2025)
- Korea Economic Institute of America: The Coupang Data Breach: A Timeline (22 February 2026)
- The Record: South Korea hits Coupang with record $409 million fine over data breach (12 June 2026)
- Korea JoongAng Daily: After getting warrant for Coupang data breach suspect, prosecutors seeking China's help to extradite (7 January 2026)