Korea fines e-commerce giant $400m over data breach affecting millions
South Korea fined Coupang a record $400m after a breach exposed data from more than 30 million customers. The company plans to challenge the decision.
Intelligence analysis by GPT-5.4 Mini

South Korea's privacy regulator says Coupang failed to protect customer data and collected personal information without legal grounds. The case is notable both for its scale and for the size of the penalty, which is the country's largest ever for a data breach.
Coupang left a huge back door open, and millions of customers' address and order details got out. South Korea's privacy watchdog gave the company a giant fine, like punishing a store for losing the keys to its biggest warehouse.
Analysis
What happened
South Korea's Personal Information Protection Commission imposed a record fine of 624.68 billion won, or more than $400m, on Coupang after a data breach that exposed the personal details of tens of millions of users. The regulator said the company violated safety obligations and collected personal data without legal grounds.
The exposed information included names, contact details, delivery information, and order histories. According to the commission, weaknesses such as poor management of authentication signing keys and access controls allowed the breach to affect around 37.5 million users. That figure is larger than half of South Korea's population.
Company response
Coupang said it deeply regrets the concern caused and plans to strengthen security measures. It also said it will challenge the regulator's decision and expects the facts to be clarified through legal procedures. The company argued that its explanations and steps to prevent further harm were not fully reflected in the ruling.
The breach first came to light in November, when Coupang said it had been alerted to an incident involving 4,500 accounts and had reported it to authorities. Later checks suggested the exposure was much larger, affecting nearly 34 million accounts in South Korea and possibly beginning as early as June through a server based abroad.
Broader context
The case adds to pressure on South Korean firms after a series of high-profile cyber-security incidents. Coupang is based in the US, but most of its revenue comes from South Korea, making the ruling especially important for its core market. The resignation of chief executive Park Dae-jun after the breach underlines how seriously the incident has damaged the company.
Key points
- South Korea fined Coupang a record 624.68 billion won, or more than $400m, over a major data breach.
- The regulator said personal data from around 37.5 million users was exposed because of weak safeguards.
- Coupang said it regrets the incident, plans to strengthen security, and will challenge the decision.
- The breach adds to wider concern about cyber-security failures at major South Korean companies.
If Coupang follows through on stronger security, the breach could lead to better protection for customer data across its platform. The case may also push other companies to tighten their own systems before regulators come after them.
If the appeal fails, Coupang faces a record penalty and more scrutiny over how it handles personal data. The breach could also erode customer trust and raise compliance costs for a company that depends heavily on the South Korean market.



