Tired of ads? Enjoy an ad-free experience by signing up.
👩‍🍳 How we use AI at Tech in Asia, thoughtfully and responsibly.
🧔‍♂️ A friendly human may check it before it goes live. More news here

South Korea ministry questions Coupang’s claims on data breach

South Korea’s Ministry of Science and ICT has criticized Coupang’s disclosure regarding a recent customer data leak, calling the company’s statement a “unilateral claim.”

Coupang, an ecommerce firm based in Seoul, said a former employee accessed basic information from about 33 million customer accounts and saved data from roughly 3,000 accounts.

The company said the individual responsible confessed and explained how the data was accessed.

The ministry said the joint public-private investigation is still ongoing, and that Coupang’s claims about the leak’s scope have not been verified.

Authorities are continuing to examine the details and circumstances of the incident.

🔗 Source: The Korea Times

🧠 Food for thought

Implications, context, and why it matters.

PIPC penalties, Coupang

  •  The PIPC has levied KRW 134.8 billion on SK Telecom for a breach that affected about 23 million users, and KRW 1.386 billion on Temu for overseas (cross-border) transfer violations 12.
  •  Coupang reports about 33 million accounts affected while authorities have not verified scope; the probe continues 13. If the PIPC confirms failures like SK Telecom’s, penalties could be large, but any estimate remains speculative 13.
  •  Logos Law Firm received a KRW 529 million fine, and firms that handle lots of personal data face tighter scrutiny under revised Personal Information Protection Act (PIPA) rules with fines up to 3% of revenue 41.
  •  Corrective orders often follow, requiring stronger safeguards and governance 1. In AI matters the PIPC has ordered data or model (machine-learning model) deletion, as in Kakao Pay/Alipay mobile payments case 5.

Insider risk, DLP spending

  •  An ex-employee accessed and saved customer data, according to Coupang 3. Authorities haven’t verified the scope, with the investigation ongoing, underscoring insider threats for companies with massive user bases 3.
  •  Investigators in SK Telecom’s case found plain-text admin credentials and missing encryption of sensitive data; SKT later announced KRW 700 billion for data protection as part of upgrades 6.
  •  Cybersecurity vendors with insider risk management plus data loss prevention (DLP) tools expect more demand as Korean enterprises focus on access monitoring plus encryption.
  •  Cybersecurity investors in venture and public markets should watch Korean DLP plus insider-threat detection startups, since enforcement pushes proactive data protection over reactive compensation 61.

Recent Coupang developments

Stay ahead in Asia’s tech landscape

You've reached your 2 free content limit for the month. Sign up for free to read the full story.

🏄 For casual readers / 👶 Free

Basic

US$0

Free forever

Get instant access to this article and more every month

0 premium content

Unlimited news briefs

5

5 articles

Ad-free reading experience

Just US$0 per day

⌛Sign up in 20s. No payment details needed.

📖 For learners / 👍 Starter

Lite

US$4.92/month

Billed annually at US$59/year

Get instant access to this article and more every month

4

4 premium content

Unlimited news briefs & articles

Ad-free reading experience

Just US$0.17 per day

Cancel anytime

Our subscriber community includes professionals from these companies:

Stay updated on the go with our mobile app.

Get latest insights with smoother, more personalized experience through TIA mobile app.