South Korea Fines Coupang $40.9 Million Over Customer Data Breach Affecting More Than 220,000 Individuals

Continue reading
South Korea's Personal Information Protection Commission (PIPC) has imposed a record 48.3 billion won ($40.9 million) fine on e-commerce giant Coupang over a 2021 personal data breach that exposed information belonging to more than 220,000 customers and employees.
According to the regulator, the incident stemmed from failures in managing personal information processed through a third-party customer service platform. It resulted in violations of the country's Personal Information Protection Act.
The enforcement action follows a PIPC investigation into how personal information was accessed, stored, and managed by an outsourced service provider. The regulator said the incident exposed weaknesses in vendor oversight, access controls, and breach reporting procedures, leading to the largest privacy-related penalty issued under South Korea's data protection framework.
According to the PIPC, the 48.3 billion won penalty represents the largest fine imposed for a violation of South Korea's Personal Information Protection Act.
The regulator concluded that Coupang failed to adequately protect personal information processed through an external customer service environment. The commission said its investigation identified shortcomings in security management practices, oversight of outsourced processing activities, and compliance with privacy protection requirements.
The PIPC also determined that contractual arrangements governing data protection responsibilities between Coupang and its service provider were insufficient to effectively mitigate risks associated with handling personal information.
According to the PIPC, the incident originated at a third-party customer service platform used by Coupang.
The regulator said that between July and August 2021, an employee working for the external service provider downloaded customer and employee information to a personal device without authorization.
The unauthorized activity continued for several weeks before being identified. The PIPC stated that the data exposure was linked to actions taken within the contractor-operated environment rather than a compromise of Coupang's core production systems.
According to the regulator, the breach affected personal information belonging to more than 220,000 individuals.
The exposed information included names, residential addresses, telephone numbers, email addresses, and partial payment card information associated with customers and employees.
The PIPC did not indicate that full payment card numbers were exposed. Publicly available information regarding the enforcement action also does not identify evidence that the exposed data was subsequently used for fraud or other malicious activity.
The PIPC said its investigation identified multiple compliance failures related to the protection of personal information.
According to the commission, access management controls were insufficient to prevent unauthorized downloading and storage of sensitive information within the outsourced environment.
The regulator also cited deficiencies in the way personal information was protected and managed by parties responsible for processing data on Coupang's behalf.
The findings formed the basis for the administrative penalty and related corrective measures imposed by the commission.
According to the PIPC, Coupang detected the unauthorized activity in October 2021.
The regulator said notification to authorities did not occur until December 2021, prompting additional scrutiny of the company's compliance with mandatory reporting requirements.
The commission concluded that the timing of the disclosure constituted part of the broader set of violations considered during the enforcement process.
Coupang disputed the regulator's conclusions and argued that the incident was caused by an employee of an external service provider rather than a breach of the company's own systems.
The company said it took action after discovering the data leak and subsequently implemented additional measures intended to strengthen information security controls.
Coupang also indicated that it may pursue administrative litigation challenging the PIPC's decision and the size of the penalty.
Neither the PIPC's findings nor public reporting on the case identified evidence that the incident involved an external cyberattack, malware deployment, ransomware activity, or exploitation of a software vulnerability.
Publicly available information also does not specify whether the downloaded data was further distributed, sold, or otherwise misused following the unauthorized access.
No threat actor, malware family, attack chain, or CVE-linked vulnerability has been publicly attributed to the incident.
The enforcement action highlights increasing regulatory attention on third-party risk management and outsourced data processing arrangements across large technology and e-commerce platforms.
The PIPC's findings emphasize that organizations can face significant penalties for failures involving contractors and service providers that process personal information on their behalf. The case also reflects broader regulatory expectations around access governance, vendor oversight, and timely breach disclosure when personal data is exposed.

A third-party software flaw inside one of Japan's largest telcos exposed login credentials for up to 14.2 million email accounts across six ISPs. The passwords? Some were hashed. Some may not have been