Coupang (CPNG) founder Kim Bom issued his first public apology for a data breach impacting 33.7 million customers, pledging compensation amid regulatory scrutiny.
The breach represents a significant reputational and regulatory risk for South Korea’s largest e-commerce platform, potentially affecting customer trust and future growth prospects.
Key Takeaways
- Data breach affected 33.7 million users, first disclosed in November
- Founder Kim Bom issued first public apology, pledges compensation plan
- Company restored leaked information, cooperating with government investigation
Market Context and Scale
The breach affects virtually all of Coupang’s 33 million active users in South Korea, making it one of the largest data security incidents in the country’s e-commerce sector 1. Coupang trades on the New York Stock Exchange and competes with global giants like Amazon and regional players including Naver and Kakao.
The incident comes as data privacy regulations tighten across Asia-Pacific markets, with potential financial penalties and operational restrictions for non-compliance.
Management Response
Kim Bom, the company’s U.S.-based chairman and founder, delivered his apology in Korean during a public statement. “I sincerely apologize for the fear and concern resulting from the breach,” Kim said, marking his first direct response since the incident was revealed in November 2.
The executive said Coupang will announce a compensation plan for affected South Korean customers “as soon as possible,” though he provided no specific details about the scope or timeline 3.
Technical Details and Recovery
Kim confirmed that the company has restored all leaked personal information while cooperating with government authorities. He said data from approximately 3,000 of Coupang’s customers was particularly compromised, though the broader breach technically affected the platform’s entire user base 4.
The company has been working with South Korean regulators since the breach was first disclosed two months ago, suggesting ongoing compliance and investigation processes.
Regulatory and Investor Implications
The incident exposes Coupang to potential regulatory penalties under South Korea’s Personal Information Protection Act. Data breaches of this magnitude typically trigger government investigations that can result in operational restrictions and significant financial penalties.
For investors, the breach raises questions about Coupang’s cybersecurity infrastructure and potential impact on user acquisition and retention in its core South Korean market, which generates the majority of company revenues.
Not investment advice. For informational purposes only.
References
1(December 28, 2025). “Coupang founder Kim Bom apologizes for data leak, pledges compensation”. CNBC. Retrieved December 28, 2025.
2(December 28, 2025). “Coupang founder Kim Bom apologises for data leak, pledges compensation”. Reuters. Retrieved December 28, 2025.
3(December 28, 2025). “Coupang founder Kim Bom apologises for data leak, pledges compensation”. China Daily Asia. Retrieved December 28, 2025.
4(December 28, 2025). “Coupang founder apologizes for data breach amid mounting scrutiny”. Korea Herald. Retrieved December 28, 2025.