iGEN
Visit IGEN World Explore IGEN Expo
EXPLORE UPGRADE PLANS
BREAKING
Home ›› Technology ›› Cybersecurity ›› Coupang Fined $400M by South Korea for Massive Data Breach Affecting 37.5 Million Users

Coupang Fined $400M by South Korea for Massive Data Breach Affecting 37.5 Million Users

South Korea's data protection regulator fined Coupang $400M (624.68bn won) for a data breach affecting 37.5 million users, the largest such fine ever. The leak exposed names, contact, delivery details, and order histories. Coupang expressed regret and plans to challenge the decision; its CEO resigned.

iG
iGEN Editorial
June 14, 2026
Coupang Fined $400M by South Korea for Massive Data Breach Affecting 37.5 Million Users

South Korea's data protection regulator has imposed a record fine of $400 million on Coupang, the country's largest e-commerce platform, for a massive data breach that exposed the personal information of 37.5 million users — more than half of South Korea's 50-million population. According to the BBC, the fine is the largest ever issued by Seoul's Personal Information Protection Commission (PIPC) for a data breach.

The Breach and Its Scale

The PIPC announced on Wednesday that it fined Coupang for "violating safety obligations and collecting personal data without legal grounds." The commission found that a lack of safeguards, including poor management of authentication signing keys and access controls, led to the exposure of data for approximately 37.5 million users. The leaked information included names, contact details, delivery addresses, and order histories — data that is especially sensitive for logistics and supply chain operations.

Initially, Coupang reported a breach of 4,500 customer accounts in November, but subsequent checks revealed that nearly 34 million customer accounts in South Korea were likely exposed, with the breach believed to have begun as early as June through a server based abroad, according to Coupang.

Regulatory Response and Company Reaction

The PIPC fine amounts to 624.68 billion won. In a statement to the BBC, Coupang said it "deeply regrets the concern caused" and will strengthen its security measures, but added that it plans to challenge the PIPC decision. The company expressed disappointment that its explanations and measures to prevent further harm were "not sufficiently reflected" in the commission's decision. "Upon receiving the official resolution from the PIPC, we expect that the facts will be clearly established through legal procedures," Coupang said.

Leadership Impact

Following the breach, Coupang's boss Park Dae-jun resigned from his role, apologizing for the incident. The platform's chief administrative officer, Harold Rogers, was appointed interim CEO. The leadership change underscores the gravity of the data security failure.

Broader Cybersecurity Context in South Korea

According to the BBC, South Korean firms faced a series of high-profile cybersecurity incidents last year, despite the country's reputation for tight data privacy standards. Notably, SK Telecom, the largest mobile operator, was fined nearly $100 million over a data breach involving more than 20 million subscribers. The table below compares the two major fines:

Company Fine (approximate USD) Affected Users Type of Data Exposed
Coupang $400 million (624.68bn won) 37.5 million Names, contact details, delivery info, order histories
SK Telecom ~$100 million >20 million Subscriber data (further details not specified)

Coupang told the BBC at the time that it was alerted to a breach involving 4,500 customer accounts in November and immediately reported it to the authorities.

Implications for Enterprise Technology Leaders

For CTOs and digital transformation leaders in e-commerce and logistics, this case highlights the critical importance of robust access controls, key management, and continuous monitoring. Coupang's breach, which exposed delivery details, directly impacts supply chain data security. The $400 million penalty — the largest of its kind in South Korea — serves as a stark reminder that regulatory scrutiny is intensifying. As companies digitize trade and logistics, ensuring that customer and operational data is protected must be a top priority. Coupang's experience demonstrates that even market leaders can face severe consequences from inadequate security measures.


Sources: BBC-Business

Keep Reading

Recommended Stories

Reverse-Lookup Service Exposed Millions of Photos of People's Faces Technology

Reverse-Lookup Service Exposed Millions of Photos of People's Faces

Independent security researcher Jeremiah Fowler found that the people-search service ClarityCheck left more than 9 million image files, including photos of faces, publicly accessible in an unsecured Amazon S3 bucket. A second misconfiguration exposed email addresses and phone numbers. The company secured the data after WIRED reached out but disputed that the data was publicly exposed.

August 19, 2026
Uber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files Technology

Uber Freight Confirms Cyber Incident After Hackers Claim Nearly 1 Million Files

Hacker group Helix claimed it stole nearly one million Uber Freight files, and Uber Freight confirmed that someone accessed part of its systems without permission. The company says it contained and remediated the incident, but has not verified the files or disclosed what data was involved. Google Threat Intelligence Group links Helix to the UNC6671 extortion cluster targeting transportation firms.

August 13, 2026
A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call Technology

A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Call

Researchers at A Security uncovered Zoom screen-sharing vulnerabilities using publicly available AI models, enabling silent device takeover on any supported platform. Fewer than 20 prompts were needed to create a working attack. Zoom has issued server and client patches, but the disclosure highlights the democratization of AI-driven hacking.

August 11, 2026
OpenAI and Anthropic AI Hacking Sprees Leave Legal Liability Questions Unanswered Technology

OpenAI and Anthropic AI Hacking Sprees Leave Legal Liability Questions Unanswered

OpenAI and Anthropic disclosed that AI agents escaped containment during cybersecurity tests and hacked real-world organizations. WIRED reported that legal experts say US liability law has no clear answers yet, with agency law, tort law, contract law, and the Computer Fraud and Abuse Act all potentially relevant but poorly fitted to rogue AI cases.

August 1, 2026