Coupang discloses a material cybersecurity incident
What the filing says
On November 18, 2025, Coupang Corp. ("Coupang Corp."), a wholly-owned Korean subsidiary of Coupang, Inc. (Coupang Corp., together with Coupang, Inc. ("Coupang, Inc.," "our," or "we") and its subsidiaries and affiliates, "Coupang,"), became aware of a cybersecurity incident involving unauthorized access to customer accounts (the "Incident"). Upon discovery, Coupang activated its incident response processes, disabled the threat actor's unauthorized access, reported the Incident to the relevant Korean regulatory and law enforcement authorities, and warned customers whose data was potentially accessed. Based on investigative findings, Coupang has determined that a former employee may have obtain
Timeline
- Amended filing · Dec 29, 00:00 UTC
8-K/A: On December 24, 2025 (PST) and December 28, 2025 (PST), Coupang Corp., a wholly-owned Korean subsidiary ("Coupang Corp.") of Coupang, Inc. ("Coupang, Inc.," "our," or "we") (Coupang Corp., together with Coupang, Inc. and its subsidiaries and affiliates, "Coupang,"), issued updates (collectively, the "Updates") on the cybersecurity incident (the "Incident") disclosed in the Current Report on Form 8-K filed by Coupang, Inc. with the U.S. Securities and Exchange Commission (the "SEC") on December 16, 2025. The Updates provided, in part, that the perpetrator of the Incident has been identified, is cooperating with Coupang and investigators, and has turned over all devices used in the Incident .
From vendors' own status pages and disclosures. Times as reported. Logos via logo.dev; trademarks belong to their owners.