인피니언 8월20일부터
This page was machine-translated and may differ from the original. View original

Coupang's personal information leak sparks a joint government-private investigation, with 30 million accounts affected.

Google 우선 소스Published2025.12.01 09:12

▲A personal information leak occurred at Coupang. (Photo: Coupang homepage capture)

Investigate violations of safety measures and impose strict sanctions if found to be in violation.
There is a high possibility of secondary damage such as smishing and voice phishing.

The Coupang breach and personal information leak were revealed to be far more serious than initially reported. Initially reported, customer information from 4,536 accounts was compromised. However, the investigation revealed that personal information, including customer names, email addresses, addresses, and phone numbers, was compromised from over 30 million accounts. Consequently, the government launched an emergency response.

The Ministry of Science and ICT (Minister Bae Kyung-hoon, Vice Prime Minister) and the Personal Information Protection Commission (Chairperson Song Kyung-hee, hereinafter referred to as the Personal Information Protection Commission) held an emergency meeting at the Government Complex Seoul on November 30 and decided to form and operate a public-private joint investigation team. The investigation team will closely analyze the cause of the accident and prepare measures to prevent recurrence.

The Personal Information Protection Commission has been conducting an investigation since November 21 after receiving two reports of data leaks from Coupang (on November 20 and November 29).

In particular, the company plans to focus its investigation on whether Coupang has violated its safety measures (access control, authority management, encryption, etc.) under the Personal Information Protection Act, and if violations are confirmed, strict sanctions will be imposed.

A government investigation revealed that attackers exploited an authentication vulnerability in Coupang's servers to access a large number of accounts without following the normal login process, stealing personal information. This resulted in the leak of contact information and addresses for a large number of citizens, increasing the risk of secondary damage, such as smishing and voice phishing.

To prevent the spread of damage, the Ministry of Science and ICT and the Personal Information Protection Commission issued a public security notice through Boho Nara (www.boho.or.kr) and will operate a three-month period of enhanced monitoring of illegal distribution of personal information on the Internet and dark web.

The types of secondary damage expected include smishing, which uses keywords such as “compensation request” and “refund” to induce users to click on malicious URLs, and phishing sites, which use search keywords such as “damage fact inquiry” to induce users to access the site by displaying it at the top of the portal. Additionally, voice phishing can be used to call victims and induce them to install a remote control app under the pretense of providing compensation or refund procedures.

The government advised the public to refrain from clicking on text messages or website addresses of unknown origin, and if in doubt, to check through the 'Smishing/Phishing Verification Service' on the Protection Nara KakaoTalk channel.

As a preventive and response method, it is required to utilize the spam reporting function when receiving text messages, report through the Voice Phishing Integrated Reporting and Response Center, and apply for a free mobile carrier number theft text message blocking service.

In addition, you should check your mobile payment history and report any damage to the cyber investigation unit of the police station. If you are infected with a malicious app, you should visit a mobile antivirus or service center to delete it. When using financial services, you should discard and reissue your public certificate or security card.

Additionally, it is important to inform those around you that you have been victimized, as malicious apps can use your address book to resend smishing messages to your acquaintances.

Minister of Science and ICT Baek Kyung-hoon said, “Citizens should be especially cautious of phone calls or text messages impersonating Coupang,” and emphasized, “The government will do its best to resolve the inconvenience and concerns of the public caused by this incident.”

Coupang CEO Park Dae-joon publicly apologized at the Seoul Government Complex on November 30th and also posted an apology on the company's website.

Meanwhile, the suspect who committed the information leak is known to be a Chinese national who worked at Coupang.
본 기사에 대한 정정·반론·추후보도 청구는 보도 청구 안내를, 그간 게재된 보도문은 정정·반론보도 모아보기를 참고해 주세요.
배종인 기자
배종인 기자