Coupang recovers smashed laptop that alleged data leaker threw into river

As part of an investigation into an insider data breach at South Korea’s largest online retailer, the company said it recovered a smashed laptop that had been bundled into a canvas bag, weighted down with bricks, and thrown into a river in an alleged attempt to destroy evidence.

Coupang, often described as South Korea’s version of Amazon, has faced widespread criticism in recent weeks after announcing in November that the personal details of 33.7 million customer accounts had been compromised by a former employee.

In a statement published over the Christmas holiday, the company defended its handling of the incident, saying it followed government orders at all times and cooperated fully with the authorities, even as it faced what it described as false accusations of negligence from “governmental agencies, the National Assembly, and parts of the media.”

Responding to “the continued misstatements that Coupang was conducting an investigation without governmental oversight,” the company revealed the details of the ongoing probe and announced a voucher scheme worth 1.685 trillion won ($1.18 billion) to compensate affected individuals.

The company said it was “fully acknowledging its responsibility for the recent personal information leak incident” with Harold Rogers, the company’s interim CEO, saying all of Coupang’s executives and employees “deeply regret the significant concern and distress the recent personal data leak has caused our customers.”

Rogers, previously the chief administrative officer of Coupang’s U.S.-based parent company, replaced Park Dae-jun who resigned amid the leak scandal in mid-December.

The voucher scheme has been criticized for only applying to Coupang’s own services and platforms, with Choi Min-hee, chair of the National Assembly’s science, technology and broadcasting committee, accusing the company of attempting to turn the crisis into a business opportunity.

“Everyone at Coupang and the government authorities has been working tirelessly together to address this critical issue, and we are now providing an important update,” the company announced.

It confirmed using “digital fingerprints and other forensic evidence to identify the former employee who leaked user data. The perpetrator confessed everything and revealed precise details about how he accessed user data,” the company stated.

Coupang said it received government approval to contact the leaker and, after an initial meeting, retrieved the leaker’s desktop and hard drives. As a result of questioning, an additional device, a MacBook Air laptop, was identified and then recovered by a diving team from a nearby river.

Despite the laptop being smashed and submerged in fresh water, Coupang said its forensics teams — comprising staff from Mandiant, Palo Alto Networks and Ernst & Young — were successfully able to document and take inventory from the device before it was handed over to government investigators.

The forensic analysis revealed that although the individual “accessed 33 million accounts,” they “only retained user data from approximately 3,000” of them which was subsequently deleted following news reports of the breach. The company said there is no evidence this data was sold or shared with third parties, though authorities continue to investigate.

Shares in the company rose 6% following its update about the investigation and tentative confirmation of the limited impact of the breach, although legal challenges — including scrutiny by lawmakers in South Korea, and a class action lawsuit pending in the United States — continue to pose a risk to Coupang’s finances.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and is also a fellow at the European Cyber Conflict Research Initiative.

 

Total
0
Shares
Previous Post

⚡ Weekly Recap: MongoDB Attacks, Wallet Breaches, Android Spyware, Insider Crime & More

Next Post

Two more banks notifying thousands of victims about Marquis Software ransomware attack

Related Posts

Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released

Ivanti has rolled out security updates to address two security flaws impacting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks, one of which has been added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities (KEV) catalog. The critical-severity vulnerabilities are listed below - CVE-2026-1281 (CVSS score:
Read More

The Hidden Risk of Orphan Accounts

The Problem: The Identities Left Behind As organizations grow and evolve, employees, contractors, services, and systems come and go - but their accounts often remain. These abandoned or “orphan” accounts sit dormant across applications, platforms, assets, and cloud consoles. The reason they persist isn’t negligence - it’s fragmentation.  Traditional IAM and IGA systems are designed
Read More

New ChatGPT Atlas Browser Exploit Lets Attackers Plant Persistent Hidden Commands

Cybersecurity researchers have discovered a new vulnerability in OpenAI's ChatGPT Atlas web browser that could allow malicious actors to inject nefarious instructions into the artificial intelligence (AI)-powered assistant's memory and run arbitrary code. "This exploit can allow attackers to infect systems with malicious code, grant themselves access privileges, or deploy malware," LayerX
Read More