Key facts
- South Korea's Personal Information Protection Commission fined Coupang 625 billion won ($409.30 million).
- The fine is the largest corporate penalty for a data breach in South Korea's history.
- Over 33 million customers' personal data was leaked.
- Coupang illegally collected data from approximately 11 million customers for marketing without consent.
- The regulator cited inadequate safety measures and systems as the cause, not sophisticated hacking.
- Coupang missed the legally mandated 72-hour detection window for the breach.
South Korea's e-commerce leader Coupang has been hit with a record 625 billion won ($409.30 million) fine by the Personal Information Protection Commission. The penalty stems from a significant data breach that exposed the personal information of over 33 million customers and the company's illegal collection of data from approximately 11 million customers for marketing purposes without consent. The regulator cited inadequate safety measures and systems as the root cause, rather than sophisticated hacking.
The breach occurred through a server based abroad, with initial checks finding nearly 34 million customer accounts in South Korea likely exposed. Coupang stated it was alerted to a breach involving 4,500 accounts in November and reported it, but later checks revealed the larger exposure. The company missed the legally mandated 72-hour detection window. Following the incident, CEO Park Dae-jun resigned, and Harold Rogers was appointed interim CEO.
This penalty is the largest corporate fine ever issued in South Korea for a data breach. The investigation into the breach has also become a point of trade friction with the United States, though South Korea maintains the probe is separate from ongoing trade talks. South Korea's largest mobile operator, SK Telecom, was also fined nearly $100 million over a separate data breach involving more than 20 million subscribers.
