ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

South Korea slaps Coupang with a record ₩624.7 billion data breach penalty

South Korea’s data protection regulator has imposed a record fine of ₩624.7 billion on Coupang, the country’s largest online retailer, after a probe into a 2025 data security breach that exposed the personal information of more than 34 million customers.

 

Coupang, also a U.S.-listed e-commerce company, experienced a major data breach in 2025 that exposed personal information of approximately 33.7 million users — about two-thirds of South Korea’s population. The breach began on June 24, 2025, but was not detected until November 18, 2025. The compromised data included customer names, email addresses, phone numbers, shipping addresses, and order histories. Importantly, no credit card information or login credentials were accessed.

 

The breach was traced to a former Coupang employee, a 43-year-old Chinese national, who retained access to internal systems after leaving the company in 2024 and exploited the authentication management system. This individual reportedly threatened to disclose the data unless security improvements were made.

 

Last week, South Korea’s privacy watchdog, the Personal Information Protection Commission (PIPC), imposed penalties against Coupang and its logistics arm, Coupang Fulfillment Services, after determining that the data breach was caused by inadequate security controls rather than an advanced cyberattack.

 

The PIPC found that the breach affected 33.2 million registered users and more than 4.3 million non-members whose personal details had been stored as delivery recipient information without their knowledge. Furthermore, the regulator urged Coupang as many as four times between December 2025 and January 2026 to notify the non-member victims, but the company failed to do so.

 

The commission has now imposed a record ₩624.7 billion fine on the company, the largest penalty it has ever issued for a personal data breach.

 

Following the PIPC’s ruling, a Coupang spokesperson told the BBC that the company “deeply regrets the concern caused,” intends to strengthen its security measures, and will challenge the regulator’s decision. The company also said its explanations and steps taken to mitigate further damage from the breach were “not sufficiently reflected” in the commission’s ruling.

 

“Upon receiving the official resolution from the PIPC, we expect that the facts will be clearly established through legal procedures,” the spokesperson added.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543