🧔♂️ A friendly human may check it before it goes live. More news here
Police raid Coupang HQ over 33.7 million user data breach
South Korean police raided the headquarters of Coupang on December 9 as part of an investigation into a major data breach affecting 33.7 million customers.
Coupang is a Seoul-based ecommerce company.
Police entered Coupang’s southern Seoul office to collect evidence on how the breach occurred, after the company revealed last month that customer data, including names, phone numbers, email addresses, and delivery details, had been exposed.
The Seoul Metropolitan Police Agency will use digital evidence to identify the source and method of the leak.
Police had previously relied on information provided by Coupang, and said they are tracking the suspect using the Internet Protocol address found during the investigation.
🔗 Source: Yonhap
🧠 Food for thought
Implications, context, and why it matters.
Coupang faces exposure under the Personal Information Protection Act (PIPA) as recent Personal Information Protection Commission (PIPC) cases carry steep fines
- South Korea’s Personal Information Protection Commission (PIPC) fined Temu KRW 1.369 billion for overseas (cross-border) transfers without disclosure and for processing Korean residents’ registration numbers (national ID numbers) 1.
- PIPC fined Meta about USD 15.67 million (KRW 21.6 billion) for collecting sensitive data from about 980,000 users without consent and for ignoring data access requests 2. Large penalties can apply even when no large breach occurs.
- Punitive damages under PIPA can reach five times actual damages for breaches caused by negligence or intent 3. Coupang faces civil liability exposure if negligence is found.
Identity protection providers in South Korea likely to see immediate demand after exposure of 33.7 million contacts
- South Korea’s fraud detection and prevention market was USD 815.70 million in 2024 and could reach USD 4,336.77 million by 2033 at a 20.40% Compound Annual Growth Rate (CAGR) 4. Breach incidents can speed adoption among consumers newly aware of their vulnerability.
- The exposed data include names, phone numbers, emails, and addresses. Risk of phishing or fraud rises 5. That can boost demand for identity protection providers (services such as credit monitoring and identity-theft alerts). Consumers may also seek dark web scanning (monitoring for stolen data on criminal marketplaces) or fraud detection services that watch for misuse of compromised contact information.
- Providers can partner with financial institutions to offer protection services. Under the PIPA, data controllers (organizations that determine the purposes and means of processing personal data) must notify affected data subjects within 72 hours of becoming aware of a leakage in specified cases, which can raise consumer attention to protective measures 3.
Recent Coupang developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




