Understanding Coupang, Inc. and the Recent Data Breach Allegations
Coupang, Inc. (NYSE: CPNG) has recently come under intense scrutiny following serious allegations about a substantial data breach affecting over 33 million accounts. Investors are understandably concerned about the implications of these events and the potential fallout for the company both reputation-wise and financially.
The Investigation by Hagens Berman
A notable law firm, Hagens Berman, is currently leading an investigation into these claims. Their team is focused on the assertion that Coupang had prominent security features in place, labeled as "proactive security" and "administrative safeguards." Yet, despite these reassurances, it is alleged that the breach went undetected for an astonishing six months.
This extended period of undetected access primarily involved a former employee who continued to have valid authentication keys even after leaving the company. The consequences of this security breach are severe, leading to a staggering compensation plan estimated at $1.2 billion, along with the resignation of key executives, including the CEO. The overall market value decline has purportedly exceeded $8 billion as a result of this incident.
The Allegations Against Coupang
At the heart of the legal claims are several significant allegations regarding Coupang's cybersecurity protocols and their lack of timely disclosure. Here’s a deeper look into these critical points:
Inadequate Security Measures
The lawsuit contends that Coupang's internal security measures were alarmingly insufficient. Allegedly, the company maintained protocols that inadvertently allowed an ex-employee to retain access to sensitive information belonging to millions of customers. Despite assurances made to investors about substantial "threat visibility," this major breach slipped past the company’s internal controls without detection for multiple months.
Delayed Disclosure
Furthermore, Coupang acknowledged that awareness of the unauthorized access incident surfaced on November 18, 2025, a shocking 11 days prior to public disclosure. Investigations have indicated that unauthorized access may have compromised critical customer information, including names, phone numbers, addresses, and email ID relating to nearly 33 million accounts. This delay in communicating such a severe security breach has angered investors, prompting further scrutiny and investigation by Korean regulators.
Impact on Business and Leadership Changes
The ramifications of this breach have triggered profound shifts within Coupang's leadership. The resignation of CEO Park Dae-joon, seemingly connected with this incident, highlights the depth of the crisis the company faces. The proposed compensation plan of approximately 1.685 trillion won, or $1.2 billion, is aimed at regaining lost customer trust and rebuilding the company’s reputation.
Next Steps for Affected Investors
For investors who purchased Coupang shares during the class period defined between May 7, 2025, and December 16, 2025, and who are now facing significant losses, it is crucial to take action promptly. Partner Reed Kathrein of Hagens Berman is available to provide guidance and assistance to those impacted by this adverse situation. The lead plaintiff deadline for this class action is approaching, set for February 17, 2026.
Frequently Asked Questions
What triggered the investigation into Coupang?
The investigation follows allegations of a severe data breach affecting over 33 million accounts, which took nearly six months to detect.
What are the immediate consequences for Coupang?
The company has faced a significant loss in market value, CEO resignation, and is dealing with a massive compensation plan aimed at customer recovery.
How can affected investors seek help?
Investors who have lost money can contact Hagens Berman for guidance and potential participation in the class action lawsuit.
What is the deadline for filing claims?
The lead plaintiff deadline for claims related to this lawsuit is set for February 17, 2026.
Why is this case significant for corporate accountability?
This case highlights critical issues of cybersecurity and corporate responsibility, particularly how companies manage sensitive information and communicate integrity to investors.