Coupang, Inc.

Dec 2025 · Graded Verified · Retail and Consumer · Government record

Incident summary

Coupang, Inc.Dec 2025
$410M
Spent responding & recovering
Direct expense
The engineer who built Coupang's alternative authentication system left at the end of 2024 with the signing key that anchored it, then spent 2025 forging his own tokens. Investigators say he cycled through member IDs, hitting the delivery-address page some 148 million times to harvest names, phones, and addresses on roughly 37 million people, then mailed sample records back as extortion. A signing key the builder can still mint is not access control; it is a master key offboarding forgot to change.
Verified: the linked document states this figure.
Retail and Consumer
SEC 8-K, Item 1.05
Initial attack type insider confirmed · Impact data theft confirmed + data extortion
Regulatory penalty
Quantified 218 days after disclosure.
What the company has said it cost
The company’s own disclosed figure, as it changed over time. The loss on the record is this same figure, typed and categorized.
2026-08-04$410MVVerifiedSEC 10-Q ↗
Corroborating records

About this record

This incident is on the public government record: an SEC 8-K filing or a state-regulator notification, graded Verified. Every figure links to the source it was read from; if we have read one wrong, tell us at info@hackerinahoodie.com. This index never sums figures across incidents. See the methodology.

Cite this incident

← The complete On the Government Record ledger ← Back to the index