Agency denies directing or ordering Coupang Inc during data breach response
South Korea's National Intelligence Service rebuffed claims made by Coupang Inc in a recent US congressional report on a personal data breach, calling the company's assertion that the NIS directed and ordered a series of actions — including the securing of IT equipment — "blatant falsehoods," and expressed regret over the matter.
In a statement Wednesday, the NIS said the report contained information "that differs from the facts." The agency said it had coordinated with Coupang Inc under Article 4 of the National Intelligence Service Act, which governs its duties, after recognizing a large-scale data leak by a foreign national as a national security threat, and that the coordination was aimed at gathering relevant information and preventing further damage.
The US House Judiciary Committee published a 35-page report Tuesday (local time) on its website titled "Blocking Competition: Korea's Discriminatory Attacks on American-Owned Companies," alleging that the South Korean government has been discriminating against Coupang Inc and other US companies.
The NIS pushed back against Coupang Inc's claim that the agency had directed the overall coordination process, saying the interactions amounted to "consultations for sharing necessary information" and that materials it received from Coupang Inc were "some of the same documents the company had already submitted to police."
The NIS also denied Coupang Inc's claim that it had suggested the company hire a specific domestic cybersecurity firm, saying Coupang Inc had itself first asked for a domestic firm referral, complaining that responses from a US firm were slow, and that the NIS had "simply shared general-level information" in response.
The agency also flatly rejected Coupang Inc's assertion that the NIS had led the recovery of IT equipment belonging to a suspect in the data breach who had fled to China, calling it "not true at all." The NIS said that until it received Coupang Inc's request to help transport the equipment back to South Korea, no one — including staff members who had been coordinating with Coupang Inc — had any knowledge of the IT equipment's existence or that Coupang Inc had secured it.
The NIS added that Coupang Inc had "first requested the transport of the equipment to South Korea through a different government agency," and that the NIS had supported the safe domestic transport of the devices solely out of concern that they could contain the personal information of some 33 million South Korean citizens and might be lost or stolen after the suspect discarded them near a stream. The agency said it "expresses regret over Coupang Inc's one-sided false claims" and would "continue to actively cooperate in all activities aimed at establishing the truth."
keg@heraldcorp.com
