Coupang fined record $410 million over 37 million-user data breach

Share:
Audio Loading voice…
Coupang fined record $410 million over 37 million-user data breach

Synopsis

South Korea's data regulator has hit Coupang with a record $410 million fine — more than triple the country's previous high — after a breach exposed 37.5 million users' personal data and the platform was found harvesting browsing records of over 11 million users without consent. The ruling redraws the compliance floor for every data-heavy platform operating in South Korea.

Key Takeaways

Coupang fined a record 624.7 billion won ($410 million) by South Korea's Personal Information Protection Commission .
The fine covers a data breach affecting 37.5 million users (33.2 million members and 4.3 million non-members), first disclosed in November 2024 .
An additional penalty of 201.1 billion won was levied for unauthorised collection of browsing data from 11.17 million users .
The total fine more than triples the previous South Korean record of 134.8 billion won against SK Telecom .
Logistics arm Coupang Fulfillment Services was separately fined 248 million won , including for maintaining a journalist employment restriction list.

South Korea's data protection authority on Thursday imposed a record fine of 624.7 billion won ($410 million) on e-commerce giant Coupang over sweeping privacy violations, including a massive data breach that compromised the personal information of more than 37 million users. The penalty is the largest ever levied by the regulator against a single company.

Breakdown of the Record Fine

The Personal Information Protection Commission (PIPC) structured the penalty in two parts: 423.6 billion won for the data breach itself, and an additional 201.1 billion won for the unauthorised collection of online user activity records and related violations. Combined, the 624.7 billion won total dwarfs the previous record — a 134.8 billion won fine imposed on wireless carrier SK Telecom Co. last August over a separate major data leak — more than tripling it.

What the Breach Involved

Coupang disclosed the large-scale breach last November, more than six months before Thursday's ruling. The compromised data included names, phone numbers, and delivery details of users across South Korea. The PIPC concluded that approximately 37.5 million individuals were affected — around 33.2 million registered members and 4.3 million non-member users who had interacted with the platform.

Beyond the breach, regulators found that Coupang had collected browsing records — including websites and applications visited — of 11.17 million users who accessed third-party services, without obtaining their consent. The company was also found to have failed to adequately oversee advertising partners that ran so-called 'hi-jacking' advertisements on its platform.

What the Regulator Said

Song Kyung-hee, chief of the Personal Information Protection Commission, said at a briefing: 'Coupang is a company that grew dramatically by offering an innovative e-commerce service based on large-scale customer information. But our investigation confirmed that it did not have a system to protect and manage personal information commensurate to that.'

The statement signals a broader regulatory posture: scale of data collection must be matched by proportionate investment in data governance — a standard that Coupang, according to the PIPC, failed to meet.

Logistics Arm Also Penalised

Separately, Coupang Fulfillment Services, the company's logistics subsidiary, was fined an additional 248 million won for distinct privacy violations. These included compiling a list of journalists and placing them on an employment restriction list — a finding that drew particular attention given its implications for press freedom and worker rights.

What Comes Next

Coupang has not yet publicly detailed whether it will contest the fines. The ruling is expected to reverberate across South Korea's tech and e-commerce sector, where data-driven growth models have outpaced regulatory compliance frameworks. This case sets a new enforcement benchmark and may accelerate legislative scrutiny of how platforms handle user data at scale.

Point of View

Compounded by active unauthorised data harvesting. The journalist blacklist finding at the logistics arm adds a governance dimension that goes beyond typical privacy enforcement. Other platforms operating large user databases in South Korea — and watching from neighbouring markets — have been put on notice that scale of data collection will now be matched against scale of accountability.
NationPress
27 Jul 2026

Frequently Asked Questions

Why was Coupang fined $410 million?
Coupang was fined 624.7 billion won ($410 million) by South Korea's Personal Information Protection Commission for two main violations: a data breach that exposed the personal information of 37.5 million users, and the unauthorised collection of browsing activity records from 11.17 million users. It is the largest privacy fine ever imposed by the South Korean regulator.
How many users were affected by the Coupang data breach?
Approximately 37.5 million individuals were affected, comprising around 33.2 million registered members and 4.3 million non-member users. The breach, which exposed names, phone numbers, and delivery details, was first reported by Coupang in November 2024.
How does this fine compare to previous South Korean privacy penalties?
The 624.7 billion won fine more than triples the previous record of 134.8 billion won, which was imposed on wireless carrier SK Telecom last August over a separate data leak. It is the highest fine ever levied by the Personal Information Protection Commission against a single company.
What was the separate violation involving Coupang Fulfillment Services?
Coupang's logistics arm, Coupang Fulfillment Services, was separately fined 248 million won for privacy violations that included compiling a list of journalists and placing them on an employment restriction list, among other infractions.
What unauthorised data did Coupang collect?
Regulators found that Coupang collected records of online activities — including websites and applications visited — of 11.17 million users who accessed third-party services, without obtaining their consent. The company was also found to have inadequately managed advertising partners running hi-jacking advertisements on its platform.
Nation Press
The Trail

Connected Dots

Tracing the thread behind this story — newest first.

8 Dots
  1. Latest 4 days ago
  2. 5 months ago
  3. 6 months ago
  4. 6 months ago
  5. 6 months ago
  6. 7 months ago
  7. 7 months ago
  8. 7 months ago
Google Prefer NP
On Google