E-commerce giant Coupang, known as the “Amazon of South Korea”, has issued a new customer notice confirming that an additional 165,000 account records were leaked in its November 2025 data breach, while South Korea’s National Intelligence Service (NIS) has publicly accused the company’s interim CEO of making false statements to lawmakers—deepening a crisis that is increasingly defined by trust, transparency, and customer experience failures.
In a notice sent to customers, Coupang said the disclosure reflects newly confirmed findings from an ongoing investigation rather than a fresh incident. The company found in November that the breach involved 33.7 million customer accounts, affecting a sizeable portion of South Korea’s population of 52 million. Coupang stated:
“This notice relates to the personal information leak incident that occurred in November 2025. It is not a new occurrence, but rather additional findings confirmed regarding that event.”
The company added that it blocked the abnormal access route immediately after discovering it and has been “continuously cooperating with investigations by relevant authorities, such as the joint public-private investigation team and the Personal Information Protection Commission.”
According to the notice, authorities determined that approximately 165,000 additional records were exposed, consisting of “address book data entered by customers (names, phone numbers, addresses).”
Coupang said it is notifying affected users “following the recommendation of the Personal Information Protection Commission,” and stressed that “payment and login information, as well as common entrance passwords, emails, and order lists, were not leaked.”
CX Fallout From an Expanding Timeline
From a customer experience perspective, the updated disclosure reinforces the uncertainty that many users have faced since the breach first surfaced. While Coupang said it has found no evidence of secondary damage so far, the need for repeated notifications has increased anxiety among customers who believed the scope of the incident had already been fully disclosed.
The breach has caused a public backlash that has seen Coupang’s active user base drop and the resignation of the company’s CEO.
Coupang’s monthly active users dropped by 1 million in January, a fall that was 10 times larger than the drop recorded between November and December, according to South Korean market intelligence firm Wiseapp.Retail.
Coupang said it will offer purchase vouchers to customers affected by the breach and repeated its apology, telling users:
“We once again sincerely apologize for causing concern to our customers.”
It has also set up a dedicated consultation line at its Personal Information Protection Center.
The retailer said it has tightened internal monitoring and put an emergency response system in place, while urging customers to stay alert for phishing and impersonation attempts. Users were advised to avoid suspicious links, double-check official communications, and be cautious of calls or messages posing as delivery drivers, recruiters, or product reviewers.




