← Coupang

2026 Coupang — 37.55M accounts; record ₩624.6B PIPC fine (Feb breach)

2026 37.5M records affected Share on X

Data compromised

Names, emails, phones, delivery addresses, order histories

Technical writeup

South Korea's Ministry of Science and ICT confirmed in February 2026 that a breach at Coupang exposed 33.7 million customer accounts after a former developer stole a signing key post-departure and forged access passes from April through November 2025. In June 2026, the Personal Information Protection Commission (PIPC) imposed a record 624.6 billion won (~$409 million) fine—the largest in South Korean history—finding personal information of approximately 37.55 million people leaked due to negligent authentication-key management, access controls, and data-destruction obligations; subsidiary Coupang Fulfillment Service was separately fined. Officials cited management failures including keys stored on a personal laptop and not invalidated after the employee left in November 2024.

Root cause

Insider threat; stolen signing key; negligent key management and access controls (PIPC findings)

References