Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Coupang reports data breach affecting 33 million customers to SEC

Coupang has reported a data breach affecting up to 33 million customers to the US Securities and Exchange Commission.

Coupang Inc., a Delaware-incorporated company operating Korea’s largest ecommerce business, said it became aware of unauthorized access to customer accounts on November 18.

The company said a former employee may have accessed names, phone numbers, delivery addresses, email addresses, and some order histories, but not banking or payment information.

Coupang said it blocked the unauthorized access, notified affected customers, and is working with Korean authorities and external forensic experts.

Korean regulators have started investigations and may impose financial penalties, though potential losses are still unclear.

Coupang said its business operations have not been materially disrupted, but acknowledged ongoing risks including possible financial losses and increased expenses.

🔗 Source: The Korea Herald

🧠 Food for thought

Implications, context, and why it matters.

South Korea’s escalating data breach penalties could pressure Coupang, but proposed 10% fines may not apply

  • Personal Information Protection Commission (PIPC) fined SK Telecom $97 million for a breach of about 23 million users 1. Coupang’s incident affecting up to 33 million customers faces the 3% revenue cap under the Personal Information Protection Act (PIPA).
  • The commission proposed a 10% revenue ceiling for repeat or intentional cases within three years or for harm to 10 million or more people due to intentional or serious negligence 2. chairperson Song Kyung-hee said applying it to earlier incidents looks unlikely, which limits Coupang’s exposure 2.
  • Past insider or access-control lapses drew KRW 529 million for Logos Law Firm 3 and KRW 6.8 billion, about $4.9 million, for LG Uplus for a 2023 breach 1. PIPC also ordered fixes at SK Telecom, such as naming a chief privacy officer (CPO) and tightening access controls 1.

Korean enterprises will accelerate insider threat detection spending post-Coupang

  • Vendors in privileged access management and insider threat detection can meet rising demand as PIPC steps up field checks tied to ISMS-P certification (Information Security Management System–Personal Information) 2.
  • North Korean operatives posing as remote IT staff with stolen identities and VPNs push interest in identity verification tools, remote access monitoring, and behavioral analytics that baseline normal activity and catch anomalies 4.
  • Investors can track prevention-first rules that drive spend on compliance automation, employee offboarding that quickly revokes access, and access monitoring to avoid future 10% revenue fine if enacted 2.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.