South Korean authorities escalated their response to a massive Coupang data breach that exposed personal information tied to about 34 million users, with the Personal Information Protection Commission investigating possible violations and weighing penalties reportedly reaching $770 million. Regulators also warned the e-commerce company could face a business suspension, while police repeatedly searched company offices and examined whether the breach involved insider activity and possible overseas data leakage. One report said investigators identified a former Chinese employee as a suspect, while officials said no malware had been found and did not rule out a state-backed angle.
The fallout reached Coupang's top leadership as the company's CEO resigned over the incident and police considered an overseas travel ban on senior executives. Investigators later questioned Coupang's interim chief for 12 hours as part of the criminal probe, and South Korean police said they would continue examining management responsibility for the breach and the company's handling of user data. The case also drew political attention abroad after a U.S. lawmaker accused Korean regulators of taking "discriminatory" action against Coupang, underscoring how the breach has become both a major privacy enforcement case and a high-profile corporate governance crisis.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
6 events from the most recent confirmed update back to the earliest known activity.
Authorities said they would question Coupang's interim CEO in the continuing investigation into the company's data breach. The planned interview reflected sustained law-enforcement pressure on senior management.
Police questioned Coupang's interim chief for 12 hours as part of the data-breach probe. The interrogation marked a major investigative step focused on executive accountability.
South Korea's Personal Information Protection Commission said it was investigating a Coupang data breach that affected about 34 million individuals. The regulator also indicated it had not found malware and was examining the possibility of a state-backed attack.
A U.S. lawmaker accused South Korean regulators of discriminatory treatment toward Coupang in connection with the company's data-breach fallout. The criticism added a political dimension to the ongoing investigation and enforcement actions.
South Korean police weighed imposing an overseas travel ban on Coupang's chief as the criminal investigation into the data breach intensified. The move signaled escalating scrutiny of company leadership.
South Korean authorities were reported to be considering possible business suspension measures against Coupang following its massive data breach. This marked an early escalation in regulatory consequences before the later PIPC investigation and police actions.
10 references tracked. Mallory keeps watching after this page renders.
economictimes.indiatimes.com
Open sourceasia.nikkei.com
Open sourcekoreatimes.co.kr
Open sourcekoreatimes.co.kr
Open sourcekoreatimes.co.kr
Open sourcebiz.chosun.com
Open sourcekoreatimes.co.kr
Open sourcekoreatimes.co.kr
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.