South Korean e-commerce giant Coupang is facing a securities class action lawsuit in the United States following a cybersecurity breach that exposed personal data belonging to more than 33 million customers.
The lawsuit was filed in federal court in California and accuses Coupang of violating US securities laws by misleading investors about its data security practices and failing to disclose the breach in a timely manner.
Allegations Against Coupang Executives
The complaint names Coupang alongside its top executives, including CEO and chairman Bom Kim and chief financial officer Gaurav Anand.
According to the lawsuit, the company and its leadership understated cybersecurity risks in regulatory filings while overstating the effectiveness of safeguards protecting customer information. Investors allege they suffered financial losses once the data breach and its scope became public.
Scope of the Cybersecurity Breach
Coupang disclosed last month that unauthorized access to internal systems led to the exposure of sensitive customer data. The breach allegedly occurred after a former employee retained system access for several months following their departure.
Compromised information included customer names, email addresses, delivery addresses, and parts of order histories. The company said payment information and login credentials were not affected.
The lawsuit claims Coupang discovered the breach on November 18 but failed to report it promptly under US securities disclosure rules.
Executive Resignation and Company Response
In the aftermath of the breach, Park Dae-jun, chief executive of subsidiary Coupang Corp, resigned earlier this month. Coupang publicly apologized to customers and pledged to strengthen internal security controls to prevent similar incidents.
Coupang did not immediately respond to requests for comment on the lawsuit, and counsel for the investor who filed the case also declined to comment.
Impact on Investors and Market Confidence
The securities class action seeks damages on behalf of investors who purchased Coupang securities between August 6 and December 16. Plaintiffs argue that accurate and timely disclosure of cybersecurity risks and incidents would have materially affected investment decisions.
The lawsuit alleges that Coupang’s US regulatory filings failed to properly disclose vulnerabilities to cyberattacks, leaving investors unaware of the company’s true exposure.
Coupang’s Market Position and Global Footprint
Often referred to as the Amazon.com of South Korea, Coupang dominates the country’s online retail sector. The company offers same-day delivery, video streaming services, and food delivery, and operates offices in California and other US cities.
The data breach has also triggered investigations by South Korean regulators, adding further pressure as the company navigates legal scrutiny on multiple fronts.
Broader Implications for Corporate Cybersecurity Disclosure
The lawsuit highlights growing expectations around cybersecurity transparency for publicly traded companies. Regulators and investors increasingly view data protection as a material risk that must be disclosed accurately and promptly.
If successful, the case could reinforce stricter standards for how companies report cyber incidents and assess potential liability for delayed or incomplete disclosures.
What Comes Next for Coupang
As the litigation moves forward, Coupang faces potential financial exposure, regulatory consequences, and reputational damage. The case adds to a growing list of investor lawsuits tied to data breaches, underscoring how cybersecurity failures can quickly escalate into securities law disputes.
For global tech and retail companies, the lawsuit serves as a reminder that data protection lapses can have consequences far beyond operational disruption.








