Coupang fined record 624.7 billion won over massive data breach, unauthorized data collection

Coupang fined record 624.7 billion won over massive data breach, unauthorized data collection

South Korea’s data protection regulator on Thursday fined e-commerce company Coupang Corp. a record 624.7 billion won (US$410 million) over privacy violations, including a massive data breach that affected more than 37 million users.

The Personal Information Protection Commission has decided to impose a record fine of 423.6 billion won for the data breach and levy an additional 201.1 billion-won fine for the unauthorized collection of records of online user activities and other violations.

It marked the largest fine ever imposed by the regulator on a single company, according to the commission.

“The investigation found that this incident happened not by sophisticated hacking, but due to Coupang’s inadequate safety management system,” Song Kyung-hee, the watchdog’s chief, said in a briefing.

Coupang expressed regret over the record fine imposed, adding that it plans to “clarify the facts through legal procedures.”

The punitive measures come more than six months after Coupang belatedly reported a large-scale data breach last November of personal information of users in South Korea, including their names, phone numbers and delivery details.

The regulator concluded that a hacker behind the breach accessed personal information of about 37.5 million users — 33.2 million Coupang members and 4.3 million others, according to Song.

The figure is sharply higher than the 33.67 million accounts earlier determined by a joint private-public probe to have been affected.

The watchdog added that it decided to file a complaint against Coupang for actions that obstructed the investigation.

The penalty for Coupang’s data breach is over three times higher than the regulator’s previous record fine of 134.8 billion won imposed in August 2025 against mobile carrier SK Telecom for a data leak that affected 23 million users.

Coupang failed to detect multiple irregularities related to the breach and did not properly manage its authentication system, the watchdog said of reasons for the record high penalties.

Under the personal information protection law, companies that suffer personal information leaks can be fined up to 3 percent of their annual sales, although sales from businesses unrelated to the violation can be excluded.

Coupang logged about 36 trillion won in annual sales on average in the past three years, according to relevant industry data.

The e-commerce company’s massive data leak had also emerged as a source of friction between Seoul and Washington after some U.S. officials and lawmakers raised concerns about whether the Korean unit of the U.S.-listed Coupang Inc. was being treated unfairly in the investigation.

Song said the watchdog’s penalty was based on the investigation results, adding that it did not consider “other influences.”

The regulator also found that Coupang collected records of online activities of 11.17 million users, who accessed other services, without their permission. The records included websites and applications visited by the users.

It additionally determined that the company did not properly manage advertisement partners that posted “hi-jacking” advertisements.

Separately, the watchdog also fined the company’s logistics arm, Coupang Fulfillment Services, 248 million won for various privacy violations, such as collecting a list of journalists and keeping them on an employment restriction list.

submitted by /u/coinfwip4
[link] [comments]

Latest News from Korea

Latest Entertainment from Korea

Learn People & History of Korea