
South Korea’s data protection regulator has imposed a record fine of ₩624.7 billion on Coupang, the country’s largest online retailer, after a probe into a 2025 data security breach that exposed the personal information of more than 34 million customers.
Coupang, also a U.S.-listed e-commerce company, experienced a major data breach in 2025 that exposed personal information of approximately 33.7 million users — about two-thirds of South Korea’s population. The breach began on June 24, 2025, but was not detected until November 18, 2025. The compromised data included customer names, email addresses, phone numbers, shipping addresses, and order histories. Importantly, no credit card information or login credentials were accessed.
The breach was traced to a former Coupang employee, a 43-year-old Chinese national, who retained access to internal systems after leaving the company in 2024 and exploited the authentication management system. This individual reportedly threatened to disclose the data unless security improvements were made.
Last week, South Korea’s privacy watchdog, the Personal Information Protection Commission (PIPC), imposed penalties against Coupang and its logistics arm, Coupang Fulfillment Services, after determining that the data breach was caused by inadequate security controls rather than an advanced cyberattack.
The PIPC found that the breach affected 33.2 million registered users and more than 4.3 million non-members whose personal details had been stored as delivery recipient information without their knowledge. Furthermore, the regulator urged Coupang as many as four times between December 2025 and January 2026 to notify the non-member victims, but the company failed to do so.
The commission has now imposed a record ₩624.7 billion fine on the company, the largest penalty it has ever issued for a personal data breach.
Following the PIPC’s ruling, a Coupang spokesperson told the BBC that the company “deeply regrets the concern caused,” intends to strengthen its security measures, and will challenge the regulator’s decision. The company also said its explanations and steps taken to mitigate further damage from the breach were “not sufficiently reflected” in the commission’s ruling.
“Upon receiving the official resolution from the PIPC, we expect that the facts will be clearly established through legal procedures,” the spokesperson added.
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543