Coupang Faces Securities Class Action Over Undisclosed Data Breach and Cybersecurity Failures
A securities class action lawsuit against Coupang, Inc. (NYSE: CPNG) alleges the e-commerce giant and its executives violated federal securities laws by failing to disclose a six-month-long data breach involving unauthorized access to sensitive customer information. The breach, enabled by inadequate cybersecurity protocols, went undetected as a former employee exploited system vulnerabilities from May 7 to December 16, 2025 the defined "Class Period" for the lawsuit.
Plaintiffs claim Coupang misled investors by omitting critical details, including: (1) the company’s weak security controls, which allowed prolonged unauthorized access; (2) the heightened risk of regulatory and legal repercussions; and (3) the failure to promptly report the breach in SEC filings, as required by law. The lawsuits argue these omissions rendered Coupang’s public statements materially false and misleading.
Two cases are currently pending: Barry v. Coupang, Inc. (No. 25-cv-10795, U.S. District Court for the Northern District of California) and Lee v. Coupang, Inc. (No. 26-cv-00047, U.S. District Court for the Western District of Washington), which expanded the class period. Investors who purchased Coupang securities during the Class Period have until February 17, 2026, to file as lead plaintiffs.
The lawsuits are led by Kahn Swick & Foti, LLC (KSF), a securities litigation firm ranked among the top 10 nationally by ISS Securities Class Action Services for settlement value. KSF, co-founded by former Louisiana Attorney General Charles C. Foti, Jr., specializes in recovering losses for investors affected by corporate fraud.
Coupang cybersecurity rating report: https://www.rankiteo.com/company/coupang
"id": "COU1768977298",
"linkid": "coupang",
"type": "Breach",
"date": "12/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'E-commerce',
'location': 'South Korea (NYSE: CPNG)',
'name': 'Coupang, Inc.',
'type': 'Public Company'}],
'attack_vector': 'Insider Threat (Former Employee)',
'data_breach': {'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': 'Sensitive customer information'},
'date_detected': '2025-12-16',
'description': 'A securities class action lawsuit against Coupang, Inc. '
'alleges the company and its executives violated federal '
'securities laws by failing to disclose a six-month-long data '
'breach involving unauthorized access to sensitive customer '
'information. The breach was enabled by inadequate '
'cybersecurity protocols and went undetected as a former '
'employee exploited system vulnerabilities.',
'impact': {'brand_reputation_impact': 'Heightened risk of regulatory and '
'legal repercussions',
'data_compromised': 'Sensitive customer information',
'legal_liabilities': 'Securities class action lawsuit, potential '
'regulatory fines'},
'investigation_status': 'Pending (Class Period: May 7, 2025 - December 16, '
'2025)',
'motivation': 'Unauthorized access to sensitive customer information',
'post_incident_analysis': {'root_causes': 'Inadequate cybersecurity '
'protocols, weak security controls, '
'failure to detect unauthorized '
'access for six months'},
'references': [{'source': 'Kahn Swick & Foti, LLC (KSF)'}],
'regulatory_compliance': {'legal_actions': 'Securities class action lawsuit '
'(*Barry v. Coupang, Inc.* and '
'*Lee v. Coupang, Inc.*)',
'regulations_violated': 'Federal securities laws, '
'SEC disclosure '
'requirements'},
'response': {'communication_strategy': 'Omissions in SEC filings, misleading '
'public statements'},
'stakeholder_advisories': 'Investors who purchased Coupang securities during '
'the Class Period have until February 17, 2026, to '
'file as lead plaintiffs.',
'threat_actor': 'Former Employee',
'title': 'Coupang Securities Class Action Over Undisclosed Data Breach and '
'Cybersecurity Failures',
'type': 'Data Breach',
'vulnerability_exploited': 'Inadequate cybersecurity protocols, weak security '
'controls'}