2026 Coupang — 37.55M accounts; record ₩624.6B PIPC fine (Feb breach)
Data compromised
Names, emails, phones, delivery addresses, order histories
Technical writeup
South Korea's Ministry of Science and ICT confirmed in February 2026 that a breach at Coupang exposed 33.7 million customer accounts after a former developer stole a signing key post-departure and forged access passes from April through November 2025. In June 2026, the Personal Information Protection Commission (PIPC) imposed a record 624.6 billion won (~$409 million) fine—the largest in South Korean history—finding personal information of approximately 37.55 million people leaked due to negligent authentication-key management, access controls, and data-destruction obligations; subsidiary Coupang Fulfillment Service was separately fined. Officials cited management failures including keys stored on a personal laptop and not invalidated after the employee left in November 2024.
Root cause
Insider threat; stolen signing key; negligent key management and access controls (PIPC findings)
References
- https://www.bleepingcomputer.com/news/security/south-korea-hits-coupang-with-record-409-million-fine-over-data-breach/
- https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?bbsId=BS074&mCode=C020010000&nttId=12171
- https://www.digitaltoday.co.kr/en/view/3520/south-korea-confirms-data-leak-of-33-7-million-coupang-accounts
- https://www.upi.com/Top_News/World-News/2026/02/10/korea-Coupang-joint-probe-data-breach-336-million-accounts/8571770709573/