South Korea fined e-commerce company Coupang a record $409 million after investigators found that a massive breach exposed the personal data of about 37.55 million people. The Personal Information Protection Commission said the leak was tied to weak basic security controls, including failures in authentication key management and access controls, and also cited violations involving data destruction, breach notification, and interference with the company's data protection officer. Authorities have identified a former Coupang IT employee as the primary suspect.
Why it matters: This is one of South Korea's largest consumer data breaches and affects a huge share of the public, making it important for customers to watch for fraud and account misuse. For defenders and privacy teams, it underscores that basic access controls, key management, and timely breach notification remain critical and that regulators are willing to impose very large penalties.
SecurityWeek News
2026.06.12
94% relevant
This article adds that South Korea's PIPC tied the penalty to security failures in access controls and authentication key management, while reporting the fine as roughly $400 million and describing exposure of more than 30 million customers.
2026.06.12
99% relevant
This is the same underlying Coupang breach and record PIPC penalty, adding specifics on the former employee’s theft of an authentication signing key, the timeline and scale of scraping activity, non-member victims, extortion emails, and the referral for criminal prosecution over deleted logs.
Sergiu Gatlan
2026.06.11
100% relevant
This article establishes a distinct tracked story by adding the regulator's formal findings, breach scope, and record penalty tied to Coupang's previously disclosed customer data leak.
← Back to all stories