Skip to content
Coupang · SEC 8-K Item 1.05Filed Dec 16, 2025

Coupang discloses a material cybersecurity incident

Material cybersecurity incidentSecurityUpdated 17h ago
Disclosed
Dec 16, 2025
Records
33M
Industry
Retail and distribution
Filings
2
Data involved
NamesEmail addressesPhone numbersPayment cardsPasswords or credentials
SEC filing

What the filing says

On November 18, 2025, Coupang Corp. ("Coupang Corp."), a wholly-owned Korean subsidiary of Coupang, Inc. (Coupang Corp., together with Coupang, Inc. ("Coupang, Inc.," "our," or "we") and its subsidiaries and affiliates, "Coupang,"), became aware of a cybersecurity incident involving unauthorized access to customer accounts (the "Incident"). Upon discovery, Coupang activated its incident response processes, disabled the threat actor's unauthorized access, reported the Incident to the relevant Korean regulatory and law enforcement authorities, and warned customers whose data was potentially accessed. Based on investigative findings, Coupang has determined that a former employee may have obtain

Timeline

  1. Amended filing · Dec 29, 00:00 UTC
    8-K/A: On December 24, 2025 (PST) and December 28, 2025 (PST), Coupang Corp., a wholly-owned Korean subsidiary ("Coupang Corp.") of Coupang, Inc. ("Coupang, Inc.," "our," or "we") (Coupang Corp., together with Coupang, Inc. and its subsidiaries and affiliates, "Coupang,"), issued updates (collectively, the "Updates") on the cybersecurity incident (the "Incident") disclosed in the Current Report on Form 8-K filed by Coupang, Inc. with the U.S. Securities and Exchange Commission (the "SEC") on December 16, 2025. The Updates provided, in part, that the perpetrator of the Incident has been identified, is cooperating with Coupang and investigators, and has turned over all devices used in the Incident .

From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.

Weekly: the week's major outages, postmortems and breaches, Saturday mornings.