South Korea’s privacy regulator has reportedly imposed a record-sized penalty on Coupang after a major data breach said to have exposed customer information on a large scale.
The reported fine, described as more than $400 million, follows an investigation by the Personal Information Protection Commission into the e-commerce company’s handling of personal data. The exact scale, timing and underlying findings have not been independently verified in this rewrite, so the figures should be read as regulator-reported or company-reported claims rather than independently established facts.
Coupang is one of South Korea’s best-known online shopping platforms, and the case has drawn attention because the reported number of affected accounts runs into the tens of millions. The exposed information was said to include names, contact and delivery details, and some order history data.
What The Regulator Said
According to the reported findings, the commission alleged that weaknesses in security controls contributed to the breach. Those alleged failures included problems around authentication signing keys and access controls.
The regulator was also reported to have announced separate penalties: one tied to the personal data breach and another connected to the collection of information without consent. The combined amount was described as the largest data-breach penalty issued by the commission, though that ranking has not been independently verified here.
Coupang said in response that it regretted the concern caused by the incident and planned to strengthen security measures. The company also indicated that it would challenge the decision once it received the official resolution, saying its explanations and steps to prevent further harm had not been fully reflected.
How The Breach Was Reported
The case followed earlier reports that Coupang had initially identified a smaller breach involving thousands of customer accounts before later checks suggested that the number of potentially exposed accounts was far higher. The company reportedly said the affected accounts were in South Korea and that the breach may have begun months earlier through a server based abroad.
The reported incident also led to leadership changes at Coupang. Park Dae-jun was said to have resigned after apologising for the breach, with Harold Rogers appointed as interim chief executive.
The Coupang case adds to scrutiny of corporate cybersecurity in South Korea after other large companies faced major privacy incidents. SK Telecom, the country’s largest mobile operator, was also reported to have received a large penalty over a separate breach involving millions of subscribers.
For Coupang, the dispute now appears likely to move into a legal process. Until that process clarifies the record, the regulator’s findings and the company’s objections remain central to understanding the case.
