Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Coupang says breach suspect identified, no data shared externally

Coupang has identified a former employee as the person behind a recent data breach but said no customer information was leaked to third parties.

The South Korea-based ecommerce firm said the ex-employee accessed data linked to 33 million customer accounts using a stolen internal security key, but only stored data from about 3,000 accounts, including names, contact details, addresses, and limited order information.

Coupang said it recovered all devices involved and deleted the stored data, adding that no payment or login details were accessed.

The company also said it submitted materials to government authorities, and that its findings so far match the employee’s statements.

However, South Korea’s Ministry of Science and ICT said Coupang’s assertions have not been confirmed, and that the matter is still under investigation by a joint team.

🔗 Source: The Korea Herald

🧠 Food for thought

Implications, context, and why it matters.

South Korea’s new penalties could hit Coupang harder

  • The government plans fines up to 10% of sales for repeat failures to protect customer data, after incidents like the Shinhan Card leak 1. Officials call Coupang’s breach a serious social crisis that erodes public trust 1.
  • A 2023 Personal Information Protection Act (PIPA) change moved regulators from voluntary fixes to strict enforcement, with penalties based on total revenue, not only revenue tied to a violation 2. Fines from the Personal Information Protection Commission (PIPC) rose from KRW 2.9 billion in 2020 to KRW 102.5 billion in 2022 2.
  • Coupang says no third-party leak occurred. ISMS-P certification can cut administrative penalties by up to 40% in breach cases, so status will shape final sanctions 3.

Security vendors can target Korea’s insider-threat market

  • An insider key compromise will push Korean firms to tighten access controls 4. Vendors with privileged access management (PAM, tools that govern and monitor admin access) can pitch products that fit Korea rules 4. Secrets management handles storing plus rotating passwords and tokens plus encryption keys while just-in-time access gives time-limited on-demand permissions 4.
  • ISMS-P requires 80 security controls and 22 personal information protection controls 5. Buyers want centralized access control, ephemeral credentials, plus tamper-proof audit logs 4. Certification for multinationals takes nine to ten months 3.
  • Mandatory Information Security Management System (ISMS) certification covers online services in Korea with KRW 10 billion in information and communication services sales or 1 million average daily users 3.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.