37,550,000
South Korea's Personal Information Protection Commission (PIPC) has imposed a record-breaking fine of 624.68 billion won (approximately $409 million USD) on e-commerce leader Coupang. The unprecedented penalty, announced on June 11, 2026, was issued for a massive data breach that exposed the personal information of 37.55 million individuals. The PIPC investigation concluded that the breach was a result of Coupang's failure to implement basic security measures, including negligent management of authentication keys and weak access controls. The company was also found to have illegally collected online activity data from 11 million customers without consent, contributing to the historic fine. Coupang has apologized but indicated it will challenge the penalty in court.
The PIPC's investigation identified several critical failures at Coupang:
This is the largest fine ever issued by the PIPC for a data privacy violation, demonstrating the South Korean government's increasingly strict stance on data protection.
The incident highlights critical compliance failures under South Korea's Personal Information Protection Act (PIPA), which requires organizations to:
The financial impact on Coupang is immediate and severe, with a $409 million fine. The reputational damage is also significant, as the regulator publicly blamed the company's negligence rather than a skilled adversary. For the 37.55 million affected customers, the leak of their personal information increases their risk of phishing, spam, and identity theft. The incident has also reportedly caused diplomatic friction between South Korea and the United States due to Coupang's U.S. incorporation.
The PIPC has exercised its authority to levy a substantial financial penalty, setting a new precedent for data breach fines in the country. The total fine of 624.68 billion won reflects a percentage of Coupang's revenue, a punitive measure allowed under South Korean law for severe violations. Coupang's plan to appeal the fine in court indicates a potentially lengthy legal battle.
This incident serves as a stark warning to all organizations, particularly those operating in jurisdictions with strict data protection laws like South Korea's PIPA or Europe's GDPR.
M1026 - Privileged Account Management.Penetration Testing and Vulnerability Scanning.Implementing strong controls over privileged accounts and secrets, such as authentication keys, is fundamental to preventing insider threats and unauthorized access.
Enforcing MFA can prevent unauthorized access even when credentials or keys are compromised.
South Korea's Personal Information Protection Commission (PIPC) announces the record fine against Coupang.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.