HackMyIP
← Back to News
2026-06-12 The Record

Coupang Hit With Record $409M Fine After Massive 33.7M User Data Breach

Data BreachRegulationAuthentication

South Korea's Personal Information Protection Commission (PIPC) has imposed a record 624.7 billion won ($409 million) fine on Coupang, the country's largest online retailer, over a data breach that exposed the personal information of approximately 33.7 million customer accounts—roughly 65% of South Korea's population. The penalty, the largest ever issued by the commission for a personal data breach, surpasses the 134.8 billion won ($88.8 million) fine levied against SK Telecom earlier this year. The regulator concluded that the breach stemmed not from sophisticated external hacking but from "deficiencies in basic safety management" by Coupang and its logistics subsidiary, Coupang Fulfillment Services.

The attack was carried out by an unnamed Chinese national and former Coupang employee who had personally developed the company's alternative authentication system before leaving at the end of 2024. After departing, he exploited a stolen signing key that underpinned the system, beginning with a test run on 95 accounts in January 2025. From April onward, he systematically cycled through member ID numbers, hitting Coupang's delivery address page approximately 148 million times over two months to harvest names, phone numbers, and addresses. He then pivoted to the account edit page, accessing it nearly 35 million times between June and October to collect names and email addresses, before adding apartment entry codes and order histories in a final phase. The breach went undetected for seven months, even as traffic on affected pages spiked to many times their normal levels and tens of millions of access attempts used non-existent member IDs. A stark reminder of why organizations must rigorously audit signing key lifecycles and authentication dependencies—users can verify their own exposure with an email breach checker.

Investigators confirmed 33,222,472 registered members were affected, but also identified a previously undisclosed category of victims: at least 4,338,368 non-members whose names, phone numbers, and addresses had been stored as delivery recipients by other customers, and who had no way of knowing their data was held by Coupang at all. The PIPC formally urged the company four times, in December 2025 and January 2026, to notify those non-member victims—Coupang failed to do so each time. The former employee later reassembled the harvested data into individual customer profiles and sent two extortion emails, the second claiming to hold 120 million addresses, 560 million order records, and more than 33 million email addresses, with sample data that included sensitive purchase histories. Coupang only became aware of the incident when a customer forwarded one of the extortion emails. The PIPC has referred Coupang for criminal prosecution over the destruction of evidence. Given the scale of credential exposure, affected users should immediately run their credentials through a password checker and rotate any reused passwords—particularly since the breach compromised email addresses that can fuel follow-on phishing and credential-stuffing attacks.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →