🧔♂️ A friendly human may check it before it goes live. More news here
South Korea president orders probe into Coupang data leak case
South Korean President Lee Jae Myung has ordered a full investigation into a major customer data leak at Coupang, an ecommerce company based in Seoul.
The breach reportedly exposed information from around 34 million cases and went undetected for five months.
During a Cabinet meeting on December 2, Lee called for strict accountability, and immediate action to prevent further misuse of leaked data.
He also urged the government to introduce stronger penalties, and improved countermeasures, referencing global standards for punitive damages.
Lee highlighted the growing frequency of data leaks and called for a new digital security framework covering both private and public sectors.
🔗 Source: The Korea Times
🧠 Food for thought
Implications, context, and why it matters.
Presidential office weighs punitive damages amid PIPA criticism
- South Korea’s Personal Information Protection Act (PIPA) caps administrative fines (regulatory penalties) at up to 3% of revenue, and analysts expect Coupang penalties could reach several hundred billion to over one trillion won 12.
- The presidential office called PIPA enforcement ‘not functioning’ 3. Rep. Choi Min-hee labeled Coupang’s breach an internal failure despite investing 1.917 trillion won in IT and 890 billion won in information security in 2025 2.
- Officials are reviewing punitive damages (court-ordered sums meant to punish and deter, beyond compensating for harm) after the Coupang breach 2 to raise penalties beyond the administrative fine structure.
- A move to punitive damages mirrors global enforcement trends and could reset compliance budgets.
Foreign cybersecurity vendors see demand under domestic representative rules
- Starting October 2, 2025, PIPA requires foreign data controllers (companies outside Korea that determine how personal data is processed) to give annual training to domestic agents (their Korea-based representatives) 4. It also adds inspections to confirm those duties.
- That shift creates demand from foreign data controllers with local agents for training programs, audit frameworks, plus monitoring tools built for Korean data protection rules.
- The amendment mandates supervision through documented inspections (recorded, auditable checks) 4, opening opportunities for third-party audit and certification services.
- Vendors can offer privileged access management (tools to manage high-risk administrator accounts) and zero-trust solutions (a ‘never trust, always verify’ security model). Authentication tokens (digital credentials that keep users signed in) stayed active for up to a decade without revocation 2.
Recent Coupang developments
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




