South Korea Fines Coupang ₩624.6 Billion Over 37M-Record Breach

The PIPC's record penalty under PIPA cites failures in access control and insider-threat monitoring tied to a 2024 intrusion attributed to a former contractor.

ThreatVectr Newsdesk· 3 min read
South Korea Fines Coupang ₩624.6 Billion Over 37M-Record Breach
Share

South Korea's Personal Information Protection Commission has imposed a ₩624.6 billion fine — roughly $409 million — on e-commerce operator Coupang, the largest penalty in the regulator's history under the Personal Information Protection Act (PIPA).

The order follows a breach disclosed in 2024 that exposed data tied to more than 37 million customers.

According to the PIPC's findings, a former contractor working on Coupang's customer service systems accessed and exfiltrated personal data over an extended period before the company detected the activity. Investigators concluded that Coupang failed to enforce adequate access controls, did not log or monitor privileged sessions sufficiently, and retained data beyond what the regulator considered necessary.

The exposed records reportedly included names, contact details, delivery addresses, and order histories.

The PIPC framed the conduct as a violation of PIPA's safeguarding obligations, which require controllers to implement technical and administrative measures proportionate to the volume and sensitivity of the data they process. The fine is calculated as a percentage of relevant revenue — a methodology the PIPC has used more aggressively since amendments to PIPA took effect in September 2023, raising the statutory cap from a fixed amount to up to 3% of revenue connected to the violating processing activity.

This is the first time the revised cap has produced a penalty at this scale against a domestic operator.

Coupang has indicated it disputes the regulator's calculation methodology and is expected to challenge the order in administrative court. Under Korean procedure, the company has 90 days from receipt of the disposition to file suit. Payment obligations are not automatically stayed by an appeal, though companies routinely seek injunctive relief.

The PIPC also issued corrective orders requiring Coupang to overhaul contractor access procedures, deploy session monitoring for privileged accounts, and submit a remediation report within a defined compliance window.

For regulated entities outside Korea, the decision signals two things worth tracking. First, the PIPC is now willing to treat insider-led incidents as enforcement events of the same magnitude as external intrusions when controls are judged deficient. Second, the revenue-based cap introduced in the 2023 amendment is operational, not theoretical. Multinationals processing Korean residents' data should reassess whether their contractor access models would withstand a PIPC investigation under the current framework.

The penalty also lands during a period of heightened cross-border coordination on data protection enforcement. The PIPC has signed cooperation arrangements with the European Data Protection Board and several APAC counterparts, and joint investigations into transfer-related violations are reportedly underway.

A full English-language summary of the disposition is expected to appear on the PIPC's enforcement actions page in the coming weeks. Companies in scope of PIPA should review their Article 29 safeguarding obligations and contractor oversight controls before the regulator's next enforcement sweep.

© 2026 Threat Vectr