Global Security Firms Warned of E-commerce Attacks Before Coupang Breach

Technology|
|
By Lee Yong-Seong
|

Global cybersecurity companies had already issued warnings about vulnerabilities across the e-commerce industry before a data breach at Coupang (CPNG) exposed personal information of 33.7 million customers, industry sources said Wednesday.

According to industry reports, global security firm Radware warned in its "2025 E-commerce Bot Threat Report" released in April that "attacks targeting mobile-based e-commerce platforms are surging as consumer transactions shift toward mobile applications."

The report found that malicious activities such as account takeovers and unauthorized data collection spiked during high-traffic periods like Black Friday and the year-end shopping season.

"When account takeovers occur, customer complaints increase and additional operational costs follow," Radware said. "If sensitive information is leaked, brand reputation damage and customer churn become severe, and the harm is even greater when payment information or personal data is involved."

Akamai Technologies, a global network solutions company, also identified lack of API authentication controls and authorization vulnerabilities as major causes of application programming interface security incidents in its "2024 Retail and E-commerce Industry Report."

Given that the core issue in the Coupang incident was a structural problem of granting excessive access privileges to internal employees, the report had effectively warned the broader e-commerce industry of similar risks.

Lee Jun-seok, leader of the Reform Party, pointed out on his social media account on the 2nd that "Coupang's API, which should have been closed and used only between internal servers, was absurdly left open and accessible to anyone on the general internet."

"Companies that conduct business using citizens' personal information must identify the information of citizens that should be protected as assets, identify vulnerabilities that may arise, and establish an information security management system accordingly," said Yeom Heung-yeol, a professor of information security at Soonchunhyang University.

Original reporting by Lee Yong-Seong for Seoul Economic Daily.

AI-translated from Korean. Quotes from foreign sources are based on Korean-language reports and may not reflect exact original wording.

Watch · Seoul Economic Daily

More →

AI KEY

Preview
Korean Corporate Intelligence HubKOSPI · KOSDAQ · 12 sectors

A live, cap-weighted view of every KOSPI and KOSDAQ sector, with same-day Korean reporting distilled by company — built for foreign investors, correspondents and analysts who need to scan Korea before the next session.

Korea Company Atlas

Preview
Market Ontology · The Feedback LoopKFTC 2025 · 92 groups · 121,954 articles

An English ontology of the Korean market — how companies, the media, the government and the National Assembly move each other in a loop. Korea's named controlling persons and designated business groups are a mechanism, not a risk to be priced blind.

SIGNAL

Pre-register
English Edition · Capital MarketsM&A · IPO · PE · Fund Flows

Pre-register for SIGNAL English Edition — a premium subscription bringing Korean capital markets coverage (M&A, IPOs, private equity, fund flows) to global institutional investors. First access to the 50% introductory rate.