Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (Cyborg)
  • No Skin
Collapse
Brand Logo

CIRCLE WITH A DOT

  1. Home
  2. Uncategorized
  3. πŸ‡°πŸ‡· South Korea's largest e-commerce retailer Coupang's data breach investigation reveals critical authentication failures

πŸ‡°πŸ‡· South Korea's largest e-commerce retailer Coupang's data breach investigation reveals critical authentication failures

Scheduled Pinned Locked Moved Uncategorized
2 Posts 1 Posters 0 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • internationalcyberdigest@infosec.exchangeI This user is from outside of this forum
    internationalcyberdigest@infosec.exchangeI This user is from outside of this forum
    internationalcyberdigest@infosec.exchange
    wrote last edited by
    #1

    πŸ‡°πŸ‡· South Korea's largest e-commerce retailer Coupang's data breach investigation reveals critical authentication failures

    Key findings:
    πŸ”Ή Signing keys were not rotated after the malicious engineer's departure, allowing continued access
    πŸ”Ή The gateway server lacked proper verification mechanisms despite being designed to restrict access
    πŸ”Ή The engineer used stolen keys to forge credentials, conducted preliminary tests, and then launched full-scale data extraction

    Link Preview ImageLink Preview Image
    internationalcyberdigest@infosec.exchangeI 1 Reply Last reply
    1
    0
    • internationalcyberdigest@infosec.exchangeI internationalcyberdigest@infosec.exchange

      πŸ‡°πŸ‡· South Korea's largest e-commerce retailer Coupang's data breach investigation reveals critical authentication failures

      Key findings:
      πŸ”Ή Signing keys were not rotated after the malicious engineer's departure, allowing continued access
      πŸ”Ή The gateway server lacked proper verification mechanisms despite being designed to restrict access
      πŸ”Ή The engineer used stolen keys to forge credentials, conducted preliminary tests, and then launched full-scale data extraction

      Link Preview ImageLink Preview Image
      internationalcyberdigest@infosec.exchangeI This user is from outside of this forum
      internationalcyberdigest@infosec.exchangeI This user is from outside of this forum
      internationalcyberdigest@infosec.exchange
      wrote last edited by
      #2

      πŸ”Ή 2,313 IP addresses were used in automated crawling operations starting in November 2024
      πŸ”Ή Attack scripts found on seized devices were capable of exfiltrating data to overseas cloud servers
      πŸ”Ή No logs remain to confirm whether data was actually transferred

      Investigators also found that Coupang had not segregated dev and production environments and that a current developer was storing a signing key on a laptop, violating the company's own internal policies.

      1 Reply Last reply
      1
      0
      • R relay@relay.infosec.exchange shared this topic
      Reply
      • Reply as topic
      Log in to reply
      • Oldest to Newest
      • Newest to Oldest
      • Most Votes


      • Login

      • Login or register to search.
      • First post
        Last post
      0
      • Categories
      • Recent
      • Tags
      • Popular
      • World
      • Users
      • Groups