Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Law Firm Investigates Coupang Security Failures After Cyber-Attack
News

Law Firm Investigates Coupang Security Failures After Cyber-Attack

Team-CWDBy Team-CWDJanuary 26, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Investors in Coupang who suffered “substantial losses” following a cyber-attack are being urged to join plaintiffs in a class action lawsuit led by US-based law firm Hagens Berman.

Coupang is an Amazon-like e-commerce platform headquartered and incorporated in the US and listed on the New York Stock Exchange. The site is particularly popular in South Korea where it is the largest online retailer.

The company’s IT systems were breached in June 2025 and the retailer confirmed in early December that the personal data of 33.7 million customers may have been exposed, including names, emails, email addresses and phone numbers.

Later in December, South Korean press agency Yonhap reported that the Seoul Metropolitan Police Agency raided Coupang’s headquarters in southern Seoul to search for internal documents and records related to the breach.

The day after the police raid, Coupang’s CEO, Park Dae-Joon, stepped down and was replaced by Seattle-based Harold Rogers, the firm’s current chief administrative officer and general counsel.

South Korea’s privacy regulator, the Personal Information Protection Commission (PIPC), also revealed that Coupang revised its terms of service in November, introducing a new clause that disclaims responsibility for any harm resulting from unauthorized third-party access to its systems.

This clause violated South Korea’s Personal Information Protection Act as it obscures the company’s accountability in cases of intentional or negligent wrongdoing. The PIPC ordered Coupang to remove the clause.

The regulator also ordered the retailer to establish a specialized task force to mitigate potential further harm to affected users.

Class Action Lawsuit to Allege Coupang’s Security Failures

In a statement published on January 23, 2026, US-based law firm Hagens Berman Sobol Shapiro LLP said the breach has led to a $1.2bn compensation plan and a loss of over $8bn in market value for Coupang.

The law firm also announced it was investigating potential security failures made by the retailer.

Coupang investors have been urged to join a class action lawsuit by the February 17 lead plaintiff deadline.

Reed Kathrein, the Hagens Berman partner leading the firm’s investigation of the claims in the pending litigation, said: “We are investigating why it allegedly took Coupang nearly six months to detect that a former employee had access to 33 million customer accounts.”

The law firm outlined some of the security failures the lawsuits will allege, including inadequate protocols that allowed a former employee to retain access to sensitive customer information.

Additionally, Hagens Berman has encouraged people who can provide non-public information regarding Coupang to help in the investigation through the US Securities and Exchange Commission’s (SEC) Whistleblower program, which involves rewards of up to 30% of any successful recovery made by the SEC.

Infosecurity contacted Coupang but the company did not respond to requests for comment by the time of publication.

Image credits: yllyso / Mamun_Sheikh / Shutterstock



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleThree Flaws in Anthropic MCP Git Server Enable File Access and Code Execution
Next Article North Korea-Linked Hackers Target Developers via Malicious VS Code Projects
Team-CWD
  • Website

Related Posts

News

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026
News

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026
News

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

2025’s most common passwords were as predictable as ever

January 21, 2026

A phishing attack that doesn’t steal your password

June 15, 2026

A quick guide to recovering a hacked account

March 21, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.