
$409M. 37.5M users. One unrevoked key.
South Korea just issued its largest-ever data protection fine — against Coupang, the country’s biggest e-commerce platform.
What The Investigation Found
• A former engineer who built Coupang’s authentication system stole the signing key before leaving. He used it for months to generate forged tokens and access customer data from overseas — undetected.
• 11.17M additional users had their browsing activity collected across third-party sites without legal basis.
• Coupang detected the breach internally on Nov 14, 2025. Notified authorities on Nov 17. That’s 48 hours — missing the legally mandated 24-hour window.
• Five months of access logs were manually deleted after a regulatory preservation order was issued.
The PIPC’s Verdict
“This was not sophisticated hacking. It was a failure of basic safety management.”
“Coupang grew dramatically using large-scale customer data. But it did not have a protection system commensurate to that.”
Key Takeaways
• Off-boarding is a compliance event. Every departing employee or contractor must trigger immediate credential and key revocation — it must be automated and audited.
• Breach notification windows are not suggestions. Notification clocks run from detection, not investigation. 24 hrs in Korea. 72 hrs under GDPR. Every hour of delay compounds the regulatory exposure.
• Log preservation is a legal obligation. Log deletion after a preservation order is obstruction — a separate violation that escalated the penalty significantly.
• Regulators are no longer asking “did a breach happen?” They are asking: “Could it reasonably have been prevented?” The PIPC investigated governance, oversight, and risk management — not just the incident. That is the new enforcement standard.
• Korea just raised its fine ceiling to 10% of revenue for intentional violations. $409M was under the old 3% cap.
At S8fe.ai, we help organisations build the data compliance infrastructure that identify risks, track remediations, and maintain audit-ready controls — automated across jurisdictions.
The breach wasn’t sophisticated. The governance failure was.
Sources:
• https://techcrunch.com/2026/06/11/south-korea-fines-coupang-409-million/
• https://www.bleepingcomputer.com/news/security/coupang-fined-409m-breach/
