기사 메일전송
Coupang's 37.5 million personal information leak and unauthorized collection... Fine of 624.7 billion won and indictment
  • Yonhap News
  • June 11, 2026 at 2:07 PM
기사수정
  • Personal Information Protection Commission imposes sanctions on Coupang... 423.6 billion KRW fine for information leakage and 211.1 billion KRW fine for unauthorized collection of member activity
  • Song Kyung-hee: "Leak not due to advanced hacking, but inadequate safety management"... Coupang to be concluded as obstructing investigation and filed a complaint.
  • Police Agency Press Corps 'Employment Restriction' Management Also Discovered... Health Information Submitted to Court Without Employee Consent


브리핑하는 송경희 개인정보위원장Song Kyung-hee, Chairperson of the Personal Information Protection Commission, briefs on the resolution of sanctions against Coupang on the 11th at the Government Complex Seoul in Jongno-gu, Seoul. The PIPC imposed a total fine of 624.6 billion won on Coupang for leaking the personal information of 37.5 million users and illegally collecting members' online activity records without legal basis. [Yonhap News]The Personal Information Protection Commission (PIPC) has imposed a total fine of 624.7 billion won on Coupang for leaking the personal information of 37.5 million users and illegally collecting members' online activity records without legal basis.


A fine of approximately 423.6 billion won was imposed for the personal information leak, and 201.1 billion won for violations such as the unauthorized collection of online activity records of over 10 million members.


This is the largest fine ever imposed for a single personal information leak incident, and also the largest fine imposed for multiple violations by a single company.


The PIPC announced on the 11th that it held a plenary meeting on the 10th at the Government Complex Seoul and resolved to impose a fine of 423.575 billion won on Coupang for violating its personal information security measures.


Additionally, a penalty of 16.8 million won was imposed for reasons such as delayed reporting. The PIPC also decided to refer the case to investigative agencies, citing that Coupang hindered the investigation into the leak incident.


The PIPC concluded that approximately 37.5 million pieces of personal information were leaked due to Coupang's insufficient basic security management system, including negligence in managing authentication signing keys and access control.


This is approximately 4 million more than the personal information leak scale (33.67 million users) reported by the joint public-private investigation team of the Ministry of Science and ICT in February of this year.


The PIPC determined that the attacker (hacker), a former Coupang employee, leaked information of approximately 33.22 million member accounts and at least 4.33 million non-members, excluding cases where information was not present in the database due to duplicate lookups or account deletions.


과징금 6천246억 부과…개인정보위, 쿠팡사태  제재안 의결 브리핑Fine of 624.6 billion won imposed... PIPC briefs on resolution of sanctions against Coupang incident [Yonhap News File Photo]

Regarding the leaked information items and scale, the hacker stole personal information such as names and emails of 33.05 million users from Coupang's member information modification page.


On the delivery address management page, delivery address information registered by at least 22.37 million members, totaling 63.98 million cases, was leaked. The leaked member delivery address information included names, phone numbers, addresses, and communal entrance passwords.


The delivery address information included the names, phone numbers, and addresses of many third parties, such as family and friends, in addition to the members themselves. At least 4.33 million non-members were identified based on their mobile phone numbers.


On the order history page, order details for 58,000 members, totaling 272,000 cases, were leaked.


Song Kyung-hee, Chairperson of the Personal Information Protection Commission, emphasized at a briefing held at the Government Complex Seoul on this day, "We have confirmed that Coupang's leak incident occurred not due to sophisticated hacking, but due to a lack of basic security management systems and negligence in management."


Violations of security measure obligations cited include the failure to securely manage user authentication methods and negligence in access control for unauthorized access and infringement incidents.


During the investigation, violations of Coupang's personal information leak notification and destruction obligations, as well as violations of the Chief Privacy Officer's (CPO) independence and obstruction of the investigation, were additionally confirmed.


Notably, it was confirmed that the CPO was excluded from Coupang's internal investigation and decision-making process regarding the leak incident and that related information was not shared.


The PIPC characterized this not as a mere internal communication breakdown, but as hollowing out the CPO system, which is core to the personal information protection framework, and effectively nullifying the CPO's independent authority to perform duties guaranteed by the Protection Act.


The PIPC issued corrective orders to Coupang, including strengthening security measures to prevent similar incidents, notifying non-members of the leak, and ensuring the CPO's substantive role.


Additionally, it recommended improvements regarding the handling of personal information of de-registered members and decided to confirm the implementation and results of measures within three months.


[그래픽] 쿠팡 개인정보 보호 위반 역대 최대 과징금 부과[Graphic] Coupang fined record amount for personal information protection violations [Seoul=Yonhap News]

In addition, the PIPC separately imposed a fine of 201.166 billion won for the violation of illegally collecting and using online activity records of approximately 11.17 million members who accessed other companies' websites and apps through Coupang, and storing this data in the DB in a state that identifies individual users.


When combined with the approximately 423.6 billion won fine for the personal information leak incident, the total amount of fines imposed by the PIPC on Coupang reaches 624.7 billion won.


Furthermore, the PIPC deemed it a violation that Coupang Fulfillment Services (CFS), a subsidiary operating Coupang's logistics centers, collected and managed a list of 71 journalists from the National Police Agency who had no history of working at the logistics centers, and registered them on an employment restriction list.


It also imposed a separate fine of 248 million won for sensitive information processing violations, specifically for submitting worker weight information, which was held and managed for the purpose of 'employee health management,' to the court during litigation related to industrial accidents.


What do you think of this article?
recommend
0
great
0
moved
0
정기구독배너
Go to Mobile Site