
Coupang has been hit with a fine of more than 620 billion won over a hacking incident that exposed the personal information of 37.5 million members. It is the largest fine ever imposed by the government for personal data breaches and related violations.
The Personal Information Protection Commission (PIPC) announced Tuesday that it had decided at a plenary meeting the previous day to impose a fine of 624.681 billion won and a penalty of 16.8 million won on Coupang.
Along with the fine, the PIPC approved corrective measures to prevent recurrence, including △strengthening security measures △notifying non-member data subjects of the breach △ensuring a substantive role for the Chief Privacy Officer (CPO). The commission plans to inspect Coupang's compliance within the next three months.
The investigation found that the large-scale data breach was caused by a former employee who had personally developed an alternative authentication system while working at Coupang. The hacker accessed Coupang's service pages and extracted the personal information, including names and emails, of a total of 33,222,472 members, as well as the personal information of 4,338,368 non-members. In particular, the hacked delivery address information included not only the members themselves but also the names, phone numbers and addresses of third parties such as family members and friends, and shared front-door entrance passwords were also leaked.
These problems were found to have arisen because basic safety management systems, such as authentication signing-key management and access controls, did not function properly. Coupang's token-based authentication system allowed authentication based solely on electronic signature verification, creating a fatal security vulnerability in which a failure to manage the keys used for signing could enable unauthorized access to all member accounts. However, even though the hacker who had access to the keys had left the company, Coupang did not immediately renew or discard them.
In addition, although numerous abnormal connections occurred during the hacker's attack period, Coupang failed to detect the irregular activity until customers who had received threatening emails from the hacker filed complaints, and it did not disclose the personal data breach to customers in a timely manner. In particular, during its internal investigation, Coupang excluded the Chief Privacy Officer (CPO) from the decision-making process. As a result, critics say, the findings of the internal investigation, which relied solely on the hacker's statements, spread without verification of the facts and caused unnecessary social confusion.
Coupang subsequently obstructed the investigation by manually deleting about five months' worth of web access logs even though the PIPC had issued an order to preserve evidence.
Coupang was also confirmed to have collected, without authorization, the online activity records of about 11.17 million members who had accessed other companies' websites and apps, and to have stored the data in a database (DB) in a state that could identify individual users. In particular, it was found that Coupang failed to properly manage and supervise advertising partners engaged in so-called "hijacking ads" that forcibly redirected users to the Coupang site even when they had not clicked, allowing records of service use against users' wishes to be indiscriminately compiled.
Coupang Fulfillment Services (CFS), Coupang's logistics subsidiary, was also fined 248 million won for violating restrictions on the collection and use of personal information and the handling of sensitive information.
CFS was found to have collected, without authorization, the personal information of 71 members of the police agency press corps who had no record of working at a logistics center, and to have registered and managed them on a so-called "employment restriction list" (blacklist). It was also found to have unlawfully processed sensitive information, including submitting to a court, without the parties' consent, workers' weight information that had been collected and retained for the purpose of "employee health management" during litigation related to industrial accidents.
The PIPC reached its final conclusion after a marathon meeting lasting more than 12 hours the previous day on the case, which drew significant attention as the largest personal data breach ever. The previous record fine was the 134.8 billion won imposed on SKT last year.
Both inside and outside the industry, there is speculation that, given the unprecedented scale of the fine, Coupang is likely to contest it, leading to a legal battle (administrative lawsuit). The PIPC's process of delivering the ruling on the disposition typically takes about one to three months, and Coupang must announce its official position, including whether it will accept the decision, or file an administrative lawsuit within 90 days of receiving the ruling.






