Internal documents show dormant authentication keys enabled months of unauthorized access to 33.7 million users’ data
A former Coupang employee is believed to have stolen personal data after leaving the company by exploiting security vulnerabilities tied to server-side authentication keys and access tokens.
According to internal documents released Monday by Rep. Choi Min-hee, chair of the National Assembly’s Science, ICT, Broadcasting and Communications Committee, Coupang failed to revoke the signing keys issued to the former employee.
The ex-staffer then allegedly used them to authenticate access tokens, or digital credentials that allow system access without requiring a separate login.
Coupang filed a criminal complaint with police Tuesday against an unidentified individual. While industry sources say the investigation has since focused on a former employee of Chinese nationality, police said no details have been confirmed at this stage.
The employee previously worked in Coupang’s authentication and access management systems, and acquired the data via an overseas internet connection, according to local reports on Monday.
The breach occurred after the suspect left the company and exercised internal access rights from outside the system. Abnormal access from a foreign internet protocol address took place from June 24 to recent weeks. Coupang first acknowledged the activity on Nov. 18, initially reporting about 4,500 affected customers.
Coupang on Saturday acknowledged a data breach affecting nearly its entire customer base of 33.7 million users, with exposed information including names, phone numbers, email addresses and home addresses.
The incident revealed serious flaws in Coupang’s security management practices, particularly in updating cryptographic signing keys used to validate access tokens after the employee’s departure.
“Although the updating of signing keys is a fundamental procedure within internal cybersecurity protocols, Coupang failed to follow it,” said Choi. “The prolonged validity of authentication keys highlights an organizational and structural failure in Coupang’s identity management system.”
Coupang stated that key expiration policies vary across the industry, typically ranging from five to 10 years. The company did not disclose the exact duration for which the compromised key remained valid.
Further police investigation revealed that Coupang had received anonymous emails threatening to disclose the data breach to the media unless the company strengthened its security posture. The message reportedly included no ransom demand.
At a regular press briefing Monday, an official from the Seoul Metropolitan Police Agency said the department had obtained server log data from Coupang.
“We are currently analyzing server log records obtained from Coupang,” the official said. “The IP address used in the attack has been identified and is under active investigation.” The official added that international cooperation is underway to trace the source.
Investigators are also working to confirm the suspect’s identity, current location and whether the individual who sent the threatening email is the same person responsible for the breach. It is also conducting a digital forensic investigation into the possibility that the stolen personal data may have already been transferred or sold to a third party.
As of press time, no secondary harm, such as voice phishing, has been reported.
Following what could be the country’s worst-ever customer data breach, Coupang could be fined as much as 1 trillion won ($680 million) under Korea’s data protection law.
Under the Personal Information Protection Act, violators may be fined up to 3 percent of their average annual revenue over the past three business years, with the calculation excluding revenue unrelated to the violation.
Coupang posted 38.3 trillion won in revenue last year and 36.3 trillion won through the third quarter of this year.
While the final amount may be reduced based on mitigating factors, the penalty is still expected to exceed the previous record of 134.8 billion won, imposed on SK Telecom in a past data breach case.
By No Kyung-min (minmin@heraldcorp.com)








