HomeIntelligenceBrief
BREACH BRIEF 🔴 Critical Breach

South Korean Regulator Fines Coupang $409 Million After Massive Personal Data Breach Affecting 33 Million Customers

South Korea’s data protection authority fined Coupang 624.7 billion won after an insider accessed and exfiltrated personal data of more than 33 million registered users and 4 million non‑member delivery recipients. The breach highlights the severe TPRM risk posed by inadequate insider‑access controls and the financial impact of regulatory penalties.

Verisq™ Intelligence · 📅 June 13, 2026 · 📰 therecord.media
🔴
Severity
Critical
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
3 recommended
📰
Source
therecord.media

South Korean Regulator Fines Coupang $409 Million After Massive Personal Data Breach Affecting 33 Million Customers

What Happened – South Korea’s Personal Information Protection Commission (PIPC) imposed a record 624.7 billion‑won fine on Coupang after an insider‑driven breach exposed the personal data of 33.2 million registered members and 4.3 million non‑member delivery recipients. The former employee stole a signing key, used it to harvest names, phone numbers, addresses, emails and order histories over several months.

Why It Matters for TPRM

  • A single insider can bypass “basic safety management” and compromise tens of millions of records.
  • Regulatory penalties can reach hundreds of millions, dramatically affecting vendor financial stability.
  • Non‑member data exposure expands liability beyond the contracted customer base, raising supply‑chain risk.

Who Is Affected – Retail & e‑commerce sector; any downstream partners that rely on Coupang’s logistics, payment processing, or data services.

Recommended Actions – Review contractual clauses on data protection and breach notification; demand evidence of robust insider‑access controls; verify that the vendor conducts regular key‑management audits and continuous monitoring.

Technical Notes – Attack vector: insider theft of a signing key (credential compromise) used to automate page scraping of delivery‑address and account‑edit endpoints. No sophisticated exploit or vulnerability was involved; the failure was in basic safety management and monitoring. Data types exfiltrated: names, phone numbers, physical addresses, email addresses, order histories. Source: The Record

📰 Original Source
https://therecord.media/south-korea-data-breach-record-fine-coupang

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Third-party risk

Does this breach reach you?

Verisq continuously monitors your vendors for breach and ransomware activity, so the question stops being whether it happened and becomes whether it reaches you.

See a live Trust Center →