창간 80주년 경향신문

“Coupang attacker viewed the delivery-address list 148 million times···includes names·addresses·shared-entrance passwords, among others”



완독

경향신문

공유하기

  • 카카오톡

  • 페이스북

  • X

  • 이메일

보기 설정

글자 크기

  • 보통

  • 크게

  • 아주 크게

컬러 모드

  • 라이트

  • 다크

  • 베이지

  • 그린

컬러 모드

  • 라이트

  • 다크

  • 베이지

  • 그린

본문 요약

인공지능 기술로 자동 요약된 내용입니다. 전체 내용을 이해하기 위해 본문과 함께 읽는 것을 추천합니다.
(제공 = 경향신문&NAVER MEDIA API)

내 뉴스플리에 저장

“Coupang attacker viewed the delivery-address list 148 million times···includes names·addresses·shared-entrance passwords, among others”

입력 2026.02.10 20:56

  • By Noh Do-Hyun

This article was translated by an AI tool. Feedback Here.

Joint public-private investigation team announces findings

33,673,817 user records leaked

Unauthorized access without going through normal login

Shortcomings noted in Coupang’s authentication system·security

Delayed reporting·violation of data-preservation order as well

Coupang headquarters in Songpa-gu, Seoul. Sung Dong-hoon

Coupang headquarters in Songpa-gu, Seoul. Sung Dong-hoon

It was found that the attacker in the Coupang personal-data leak extracted users’ personal information through abnormal access, including viewing the delivery-address list pagecontaining names·phone numbers·addressesabout 148 million times. On the “Edit My Info” page, name·email information for 33.67 million records was found to have been leaked. The Personal Information Protection Commission will finalize the detailed scope of the personal-data leak at a later date.

On the 10th, the Ministry of Science and ICT announced the findings of a joint public-private investigation team into the Coupang breach. Earlier, the incident erupted when a former employee of Chinese nationality, identified as Mr. A, who had handled authentication system development at Coupang, leaked users’ personal information on a massive scale.

According to the team, the attacker sent Coupang two emails on November 16 and 25 last year stating that information had been exfiltrated. The attacker claimed to have leaked more than 120 million delivery-address data, more than 560 million order data, and more than 33 million email address data.

The team stated, “After the attacker leaked names·emails from Coupang’s Edit My Info page, names·phone numbers·addresses·shared-entrance passwords from the delivery-address list page, and information on items users ordered from the order list page, they included part of that data in an email sent to Coupang.”

The team also confirmed, through analysis of Coupang’s web and application access records (logs), that user information was leaked from pages including Edit My Info, the delivery-address list, and the order list.

From the Edit My Info page, it verified that 33,673,817 user records containing name and email were leaked.

Additionally, the attacker viewed the delivery-address list pagewhich contains name, phone number, delivery address, and shared-entrance passwords masked with special characters148,056,502 times to siphon information. The delivery-address list page contains a large amount of information not only about the account holder but also about third parties such as family and friends, including their names, phone numbers, and delivery addresses.

The page for editing the delivery-address list, which includes shared-entrance passwords in addition to name, phone number, and delivery address, was also viewed 50,474 times. The order list page, which shows a user’s recently ordered items, was viewed 102,682 times.

Provided by the Ministry of Science and ICT

Provided by the Ministry of Science and ICT

The team said, “We estimated the scale of the leak based on web access records and other sources,” adding, “The Personal Information Protection Commission will later finalize and announce the size of the personal-data leak.”

It was found that the attacker exploited an authentication vulnerability on Coupang’s servers to access user accounts abnormally without a normal login and exfiltrate information without authorization.

Under normal usage, a user goes through the login process to receive an “electronic pass.” Coupang’s gateway server verifies whether the issued electronic pass is valid and, if there is no issue, allows access to the service.

The attacker stole the signing key of the user authentication system they had administered while employed, then used it to forge·alter electronic passes and bypass Coupang’s authentication framework. As a result, they were able to access Coupang’s services without going through the normal login procedure.

The team pointed out that Coupang’s information protection management system, including its user authentication framework and key management, was inadequate. Legal violations also occurred, including delayed incident reporting and noncompliance with data-preservation orders.

Based on the team’s findings, the Ministry of Science and ICT will require Coupang to submit, by this month, an implementation plan for recurrence-prevention measures and will check whether it is carried out. For items needing improvement identified through the implementation review, corrective action will be ordered under the Information and Communications Network Act.

  • AD
  • AD
  • AD
뉴스레터 구독
닫기

전체 동의는 선택 항목에 대한 동의를 포함하고 있으며, 선택 항목에 대해 동의를 거부해도 서비스 이용이 가능합니다.

보기

개인정보 이용 목적- 뉴스레터 발송 및 CS처리, 공지 안내 등

개인정보 수집 항목- 이메일 주소, 닉네임

개인정보 보유 및 이용기간- 원칙적으로 개인정보 수집 및 이용목적이 달성된 후에 해당정보를 지체없이 파기합니다. 단, 관계법령의 규정에 의하여 보존할 필요가 있는 경우 일정기간 동안 개인정보를 보관할 수 있습니다.
그 밖의 사항은 경향신문 개인정보취급방침을 준수합니다.

보기

경향신문의 새 서비스 소개, 프로모션 이벤트 등을 놓치지 않으시려면 '광고 동의'를 눌러 주세요.

여러분의 관심으로 뉴스레터가 성장하면 뉴욕타임스, 월스트리트저널 등의 매체처럼 좋은 광고가 삽입될 수 있는데요. 이를 위한 '사전 동의'를 받는 것입니다. 많은 응원 부탁드립니다. (광고만 메일로 나가는 일은 '결코' 없습니다.)

뉴스레터 구독
닫기

닫기
닫기

뉴스레터 구독이 완료되었습니다.

개인정보 수집 및 이용
닫기

개인정보 이용 목적- 뉴스레터 발송 및 CS처리, 공지 안내 등

개인정보 수집 항목- 이메일 주소, 닉네임

개인정보 보유 및 이용기간- 원칙적으로 개인정보 수집 및 이용목적이 달성된 후에 해당정보를 지체없이 파기합니다. 단, 관계법령의 규정에 의하여 보존할 필요가 있는 경우 일정기간 동안 개인정보를 보관할 수 있습니다.
그 밖의 사항은 경향신문 개인정보취급방침을 준수합니다.

닫기
광고성 정보 수신 동의
닫기

경향신문의 새 서비스 소개, 프로모션 이벤트 등을 놓치지 않으시려면 '광고 동의'를 눌러 주세요.

여러분의 관심으로 뉴스레터가 성장하면 뉴욕타임스, 월스트리트저널 등의 매체처럼 좋은 광고가 삽입될 수 있는데요. 이를 위한 '사전 동의'를 받는 것입니다. 많은 응원 부탁드립니다. (광고만 메일로 나가는 일은 '결코' 없습니다.)

닫기