Coupang submits investigation findings to SEC as Korean government objects

Coupang disclosed the results of its investigation into a recent data breach by submitting them to the U.S. Securities and Exchange Commission (SEC) on Monday, despite the Korean government’s rejection of the findings. The New York-listed e-commerce giant presented the outcomes of its internal probe into a massive personal data breach, which impacted fewer customers, as well as its proposed compensation scheme for affected individuals in its filing with the SEC.

The submission sent through the SEC’s Electronic Data Gathering, Analysis, and Retrieval system included a signed statement by Harold Rogers, Coupang’s interim CEO in Korea and the chief administrative officer and general counsel of its American parent company. The disclosure stated, “The investigation suggests that while about 33 million accounts were accessed, the wrongdoer only retained limited data from roughly 3,000 customer accounts, and this customer information has been removed without being shared with a third party.”

However, the Korean authorities strongly opposed Coupang’s declaration last Thursday, expressing disappointment and frustration over what they labeled a “one-sided proclamation.” The Ministry of Science and ICT swiftly responded, mentioning that Coupang’s statement had not been validated by the government-led joint investigative team.

Furthermore, the Seoul Metropolitan Police Agency mentioned they were still scrutinizing the information and electronic devices provided by Coupang, continuing their comprehensive examination. Coupang’s SEC disclosure did not address these objections, but it did include the firm’s press release from Friday defending itself against accusations of a “self-investigation.”

The company asserted that the probe was not internal but conducted over multiple weeks under government directives. It mentioned that ongoing misrepresentation that the inquiry lacked oversight was causing unwarranted public distress. Coupang claimed they contacted the alleged leaker on the government’s suggestion, retrieved the suspect’s desktop and hard drives, and relinquished them to the authorities. They also secured the suspect’s laptop, conducted a forensic analysis, and then turned it over to the government.

In addition, Coupang unveiled a consumer compensation program offering vouchers totaling 1.685 trillion won ($1.17 billion) to users informed of the breach in late November. The vouchers can be utilized for purchases on Coupang, and the expense will be deducted from each transaction’s sales revenue, signifying the company’s intention to inform investors about the anticipated financial impact.

Critics swiftly criticized the compensation plan, which provides 50,000 won in vouchers to each affected user, as seeming unfair. The vouchers are allocated as 5,000 won for Coupang’s general marketplace, 5,000 won for Coupang Eats, 20,000 won for Coupang Travel, and 20,000 won for Coupang R.LUX. Critics accused the company of employing bait marketing by offering low-value coupons for the main marketplace and high-value vouchers for higher-priced services to entice additional spending.

Despite facing backlash and escalating tensions with the Korean government, Coupang proceeded with the SEC filing, likely due to concerns about violating SEC regulations by not promptly disclosing such a financially significant matter. Minister of Science and ICT Bae Kyung-hoon reiterated on Tuesday that more than 33 million data entries had been compromised, contradicting the company’s findings. Bae expressed disagreement with Coupang’s assertions and emphasized the need for verified information, casting doubt on the thoroughness of the company’s investigation.