South Korea’s Personal Information Protection Commission imposed a record 624.6 billion won fine on Coupang, plus 248 million won on subsidiary Coupang Fulfillment Service, after a breach exposed personal data tied to roughly 34 million to 37.55 million people. Regulators said the incident stemmed from weak security controls, including poor authentication key management and inadequate access restrictions, and that exposed data included names, email addresses, shipping addresses, phone numbers, and order histories. Authorities said the breach began in 2025 and persisted for months before discovery, making it one of the country’s largest retail-sector privacy incidents.
The commission also cited Coupang for failures involving data destruction, breach notification, interference with the independence of its data protection officer, and obstruction of the investigation. Investigators identified the main suspect as a former Coupang IT employee, described in one report as a 43-year-old Chinese national, who allegedly retained sensitive data on multiple hard drives and tried to destroy evidence by discarding a laptop in a river. Coupang said it plans to challenge the penalty, disputed aspects of the exposure, and maintained the stolen data was limited, deleted from recovered devices, and not shared onward.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
During its breach investigation, South Korea’s Personal Information Protection Commission found Coupang deleted and failed to preserve key access logs after being ordered to retain them. The regulator referred the company for criminal prosecution over evidence destruction.
After the fine was announced, Coupang said it plans to challenge the South Korean regulator’s decision. The company also said the suspect retained data for roughly 3,000 accounts, that the data was deleted from all devices, and that it was not transferred to others.
South Korea’s Personal Information Protection Commission imposed a record fine of about 624 billion won on Coupang, with an additional penalty on subsidiary Coupang Fulfillment Service, over a breach affecting tens of millions of people. The regulator cited weak access controls, poor authentication key management, and other privacy-law violations.
In mid-November 2025, Coupang disclosed that 33.7 million accounts had been compromised. TechCrunch separately reports the breach was discovered in December 2025 after months of unauthorized access.
South Korean regulators said the Coupang breach began in late June 2025 and continued for months, exposing customer personal information due to inadequate security controls.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
5 references tracked. Mallory keeps watching after this page renders.
bankinfosecurity.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourcebbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.