Tehran-linked hackers are turning a distant war into a live resilience test for Australia, probing Five Eyes networks as local banks quietly move to high alert while hybrid warfare becomes a “when, not if” cyber disruption scenario.
Five Eyes nations, led by Australia's ASD, have issued an urgent warning for a critical zero-day (CVE-2026-20127) in Cisco's SD-WAN products. The flaw, actively exploited since 2023 by a sophisticated actor, allows for complete network takeover and impacts critical infrastructure globally.
This week’s tech earnings put Nvidia back under the spotlight, as blockbuster AI-driven results clashed with a skittish market that still sold the stock off—capturing the tension between hard data on acceleration and deep-seated fears of an AI overreach.
2nd December 2025 Cyber Update: Coupang Data Breach Exposes 33.7 Million Customers
South Korean e-commerce giant Coupang has confirmed a massive data breach exposing the personal information of 33.7 million customers. The incident, which began in June 2025, is one of the largest in the nation's history and is linked to a former employee's active credentials.
Cyber News Centre's cyber update for 2nd December 2025: Coupang has confirmed a significant data breach affecting over 33 million of its customers.
Coupang is South Korea's largest online retailer, often described as the nation's equivalent of Amazon.com. The company, founded in 2010 and backed by SoftBank Group, offers a wide range of services including its popular "Rocket Delivery" and is expanding into food delivery, streaming, and fintech.
The Update and Why It Matters
Update: South Korean e-commerce giant Coupang has confirmed a data breach that exposed the personal information of 33.7 million customers, making it one of the largest in the country's history. The breach, which began on June 24, 2025, was not detected until November 18. Exposed data includes customer names, email addresses, phone numbers, and shipping addresses, though the company states that financial details and login credentials were not compromised. An investigation by South Korean police points to a former employee, a Chinese national who has since left the country, as a key suspect. It is believed the individual used an authentication key that remained active after their employment was terminated, allowing prolonged access to the company's servers. Coupang CEO Park Dae-jun issued a public apology, stating,
"We sincerely apologise once again for causing our customers inconvenience."
The company is cooperating with authorities and has retained an independent security firm.
U.S. national Kim Beom-su, founder and chairman of Coupang, maintains effective control over Coupang—the leading e-commerce platform in South Korea—through his ownership of 74.3% of the voting rights in Coupang Inc., a U.S.-listed entity that wholly owns (100%) the Korean operating subsidiary. His continued behind-the-scenes influence has drawn increasing criticism, particularly in the wake of Korea’s largest-ever data breach involving Coupang. The accompanying photo shows Kim at the New York Stock Exchange on March 11, 2021 (local time), commemorating Coupang Inc.’s IPO. (Source: Coupang)
Why it Matters: This incident highlights a critical failure in internal security controls, specifically the lack of a robust offboarding process for employees with privileged access. The fact that a former employee's credentials remained active for months demonstrates a significant gap in identity and access management. For a company of Coupang's scale, which handles the data of over half of South Korea's population, this oversight is a major concern. The breach serves as a stark reminder that even sophisticated e-commerce platforms can be compromised by basic security hygiene failures, and that the insider threat, whether malicious or negligent, remains a potent risk.
Get the stories that matter to you. Subscribe to Cyber News Centre and update your preferences to follow our Daily 4min Cyber Update, Innovative AI Startups, The AI Diplomat series, or the main Cyber News Centre newsletter — featuring in-depth analysis on major cyber incidents, tech breakthroughs, global policy, and AI developments.
Sign up for Cyber News Centre
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead.
Tehran-linked hackers are turning a distant war into a live resilience test for Australia, probing Five Eyes networks as local banks quietly move to high alert while hybrid warfare becomes a “when, not if” cyber disruption scenario.
Five Eyes nations, led by Australia's ASD, have issued an urgent warning for a critical zero-day (CVE-2026-20127) in Cisco's SD-WAN products. The flaw, actively exploited since 2023 by a sophisticated actor, allows for complete network takeover and impacts critical infrastructure globally.
Canadian transcription firm VIQ Solutions has admitted to a significant data breach after subcontracting work to an Indian firm, e24 Technologies, exposing highly sensitive Australian federal and state court files. The incident, raises major national security concerns
Sydney-based fintech youX has confirmed a massive data breach exposing the personal and financial details of 444,538 Australian borrowers. An unsecured database left 141GB of data, including loan applications, driver's licences, and residential addresses, accessible for at least 10 months.
Where cybersecurity meets innovation, the CNC team delivers AI and tech breakthroughs for our digital future. We analyze incidents, data, and insights to keep you informed, secure, and ahead. Sign up for free!