Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

Police examine suspect’s laptop in Coupang data leak probe

South Korean police are examining a laptop submitted by Coupang as part of a probe into a major data leak at the ecommerce firm.

The Seoul Metropolitan Police Agency’s cyber unit is conducting a forensic analysis to determine if the device was used by the suspect and to check for possible tampering during its submission.

Coupang identified a former employee as the suspect and said the individual confessed to accessing customer data.

The company said it has recovered personal information for around 3,000 affected customers and claimed no data was shared outside the company.

Police are also reviewing the company’s handling of the case, including its direct contact with the suspect and its retrieval of the laptop using divers, to assess potential legal issues.

🔗 Source: Yonhap

🧠 Food for thought

Implications, context, and why it matters.

Coupang’s insider breach may trigger PIPC fines beyond the immediate exposure

  • PIPC is South Korea’s data protection regulator. It fined Golfzon KRW 7.5 billion for security failures 1 and Modutour KRW 757.2 million for Personal Information Protection Act (PIPA) violations 2, which puts Coupang at risk of sanctions.
  • Coupang contacted the suspect and sent divers for the laptop, which raises questions about chain-of-custody procedures (the documented control of evidence from collection through analysis) under PIPC’s governance focus 3.
  • Past incidents in 2020–2021 and a 22,000-customer seller system breach in December 2023 4 raise the chance of tougher penalties under PIPC’s 2023 revision that allows fines up to 3% of total revenue for specified security failures 1.

Security vendors and consultants face rising demand under Korea’s stricter insider threat enforcement

  • PIPC’s push for prevention and accountability 5 is fueling demand for digital forensics with incident response (DFIR) that documents proper evidence handling, a gap exposed by the diver-retrieved laptop.
  • Operators that handle Korean user data should invest in insider threat detection with data loss prevention (DLP) tools, since PIPC has penalized weak oversight of third-party processing, including poor monitoring (outsourcing data handling to vendors) 6.
  • Privacy consultancies can help foreign entities designate domestic representatives (a local point of contact empowered to liaise with regulators; mandatory from October 2025 for large personal data processors) 1 and build audit trails that meet PIPC’s governance expectations 3, with a focus on firms with prior breaches.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.