Coupang Forms External Security Panel After Data Breach Affecting 33 Million Users
Coupang has launched a quarterly external advisory committee to review its information-security policies, track emerging threats and recommend operational changes after a major customer-data breach disclosed last year.
Coupang has established an external information security advisory committee as the South Korean e-commerce company works to strengthen customer-data protections and rebuild trust following a major breach disclosed last year.
The company said Tuesday that the panel will provide objective reviews of its internal security policies and recommend ways to improve safeguards. Seven outside specialists from the fields of information security, law, management and information technology will participate, giving the company a broader pool of expertise for assessing both technical threats and governance issues.
The committee will be co-chaired by Heo Sung-wook, chair of the Korea Chief Privacy Officers' Forum, and Coupang Chief Information Security Officer Brett Matthes. Heo previously served as director general of the Network Policy Office at the Ministry of Science and ICT and as president of the National IT Industry Promotion Agency.
Other members include Kang Eu-mene, an adviser at Kim & Chang; Kwak Jin, a professor at Ajou University; Kim Hyun-kyung, a professor at Seoul National University of Science and Technology; Ahn Jeong-ho, an attorney at Shin & Kim; Yang Je-yul, a professor at Kyung Hee University; and Chang Hang-bae, a professor at ChungAng University.
The committee held its inaugural meeting on Tuesday and is expected to meet once every quarter. Its work will include reviewing changes to relevant laws and regulations, monitoring emerging security threats, examining unresolved issues and advising on Coupang's wider information-security policies.
Coupang said it plans to reflect the committee's recommendations in its internal policies and operational processes. The company also briefed members on its existing efforts to protect customer data and pledged to maintain active communication with the panel. The stated goal is to build an independent and professional review structure while raising security practices to what the company described as leading global standards.
The governance move follows intense criticism after Coupang announced in November 2025 that personal information belonging to more than 33 million users had been affected by a data breach. The scale of that incident placed pressure on the retailer to demonstrate that security improvements would extend beyond internal reviews.
By giving external specialists a recurring role, Coupang is creating a formal channel through which legal, technical and management concerns can be assessed together. The practical impact will depend on how quickly recommendations are incorporated into day-to-day operations and whether the quarterly process produces measurable improvements in protecting customer information.
