---
title: "South Korea fines Coupang $400m over data breac… | Firevault"
url: https://fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers
description: "South Korea has issued its largest-ever data breach fine, penalising e-commerce giant Coupang more than $400m after the personal data of 37.5 million…"
lang: en-GB
---

News · News (Threat Analysis) · 14 June 2026

# South Korea fines Coupang $400m over data breach affecting 37.5 million customers

South Korea has issued its largest-ever data breach fine, penalising e-commerce giant Coupang more than $400m after the personal data of 37.5 million customers, more than half the country's population, was exposed.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

5 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouth-korea-fines-coupang-400m-data-breach-37m-customers
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouth-korea-fines-coupang-400m-data-breach-37m-customers&text=South%20Korea%20fines%20Coupang%20%24400m%20over%20data%20breach%20affecting%2037.5%20million%20customers%0A%0ASouth%20Korea%20has%20issued%20its%20largest-ever%20data%20breach%20fine%2C%20penalising%20e-commerce%20giant%20Coupang%20more%20than%20%24400m%20after%20the%20personal%20data%20of%2037.5%20million%20customers%2C%20more%20than%20half%20the%20country%27s%20population%2C%20was%20exposed.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fsouth-korea-fines-coupang-400m-data-breach-37m-customers

Image: Coupang employees load items into a delivery truck at one of the company's centres in Seoul (https://fire-vault.com/news/south-korea-coupang-breach-hero.jpg)

Coupang employees load items into a delivery truck at one of the company's centres in Seoul

Why it matters

## What this means for organisations holding critical data

South Korea''s Personal Information Protection Commission (PIPC) has handed e-commerce giant Coupang a record fine of more than $400m (£299m) over a data breach (https://fire-vault.com/learn/breaches) that exposed the personal information of more than 37.5 million customers. It is the largest data breach penalty ever issued by the regulator, and a stark warning to any organisation holding population-scale customer data inside live, internet-connected systems.

## What happened

The PIPC announced a 423.6bn won fine for the data breach itself, with a further 201bn won added for the non-consensual collection of information. The commission concluded that a lack of safeguards, including poor management of authentication signing keys and weak access controls, had resulted in the names, contact details, delivery addresses and order histories of roughly 37.5 million users being exposed.

Coupang first told authorities in November that around 4,500 accounts had been affected. Later checks revised that figure to nearly 34 million accounts, with the intrusion believed to have started as early as June through a server based abroad. Following the breach, Coupang''s chief executive Park Dae-jun resigned, and chief administrative officer Harold Rogers was appointed interim CEO.

## Why this breach is so significant

Coupang is South Korea''s dominant e-commerce platform, often described as the country''s Amazon. The 37.5 million figure represents more than half of South Korea''s population of around 50 million. Few breaches in any market reach that level of national exposure.

Two details from the PIPC findings matter most for security leaders:

- Authentication signing keys were not properly managed
- Access controls were not sufficient to contain the intrusion

Together, those two failures allowed an attacker who reached a foreign-hosted server to pivot into systems holding tens of millions of customer records. This is not a story about a single zero-day or a clever phishing lure. It is a story about how connected systems, weak key hygiene and broad access combine into a worst-case outcome.

## The regulatory pattern is hardening

The Coupang fine follows a series of high-profile South Korean cyber incidents, including a nearly $100m penalty against mobile operator SK Telecom over a breach affecting more than 20 million subscribers. Regulators across Asia, the EU and the UK are moving in the same direction: larger fines, faster enforcement, and reduced tolerance for organisations that treat data protection as a paperwork exercise.

For UK and EU operators, the read-across is clear. The ICO, the Garante, the CNIL and others are watching the same risk surface. The combination of poorly managed cryptographic material and overly broad system access is increasingly treated as gross negligence rather than misfortune.

## The Firevault view

Mark Fermor, Director and Co-co-founder of Firevault, on what the Coupang case shows:

"Every breach of this size has the same shape. Live data, connected systems, signing keys held inside the blast radius, and access controls that look fine on a diagram and fail in practice. Once an attacker is past the perimeter, scale is just a query.

"Offline secure storage (https://fire-vault.com/offline-secure-storage) is not a backup strategy. It is a containment strategy. If your most sensitive cryptographic material and your authoritative customer records sit behind a physical boundary that an attacker cannot reach over a network, the worst day looks completely different. You lose a server, not a country.

"Firevault and Firebreak exist to make that boundary real. Hardware-enforced isolation for the data and the keys that matter most, with controlled, auditable paths in and out. That is what regulators are increasingly expecting to see, and it is what stops a single intrusion turning into a national-scale fine."

## What organisations should take from this

- Treat signing keys, root credentials and master records as crown jewels that must live outside live, internet-facing systems wherever possible
- Assume any user-facing service can be reached, and design containment so that reach does not equal exposure
- Test access controls against realistic attacker paths, not just policy documents
- Plan for regulator scrutiny in proportion to the data you hold, not the revenue you earn

Coupang''s fine is not an outlier. It is the new baseline for organisations that store population-scale data on always-connected infrastructure. The defensible posture is to put the data that would end your business behind a boundary that the internet cannot cross.

Learn more about how Firevault protects enterprise data with offline secure storage, or explore the Control (https://fire-vault.com/control) deployment model for hardware-enforced isolation of sensitive systems.

**How Firevault helps**

- **Offline Secure Storage (https://fire-vault.com/offline-secure-storage)** keeps gold-copy data physically disconnected from the network, so a ransomware or exfiltration event cannot reach it.
- **Control (https://fire-vault.com/control)** gives boards and operators a single view of what is online, what is isolated, and what is recoverable across the estate.
- **Firebreak (https://fire-vault.com/firebreak)** delivers hardware-enforced disconnection at Layer 1, so exposed credentials or compromised network paths cannot become a route into the vault.

_Talk to Firevault about Disconnect to Protect® (https://fire-vault.com/about) for your organisation._

Sources

## Where this reporting comes from

01

**Original report**Primary coverage referenced in this analysis View original article (https://www.bbc.co.uk/news/articles/cvgj4rgz2n2o)

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Hardware**Your copy sits on dedicated encrypted hardware

**Disconnect**Offline by default, connected only when you say so

**Recovery**A known-clean copy to rebuild from, on your timetable

**Location**Held in a secure Firevault Bunker

Related Reading

## You may also find these useful

Breach Analysis

### Dyfed-Powys Police confirms cyber attack as staff information may have been compromised

Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

25 Sept 2026 3 min
https://fire-vault.com/news/dyfed-powys-police-cyber-attack-2026

Industry Insight

### Morgan Stanley email error exposed an internal list of more than 100 potential deals

A senior banker accidentally sent clients an internal deal-pipeline attachment. The incident was not a cyberattack, but it shows how one ordinary email can turn confidential working information into a market-integrity and client-trust problem.

25 Sept 2026 6 min
https://fire-vault.com/news/morgan-stanley-email-error-deal-list-2026

Threat Analysis

### Fake job interviews infected 30,000 devices, FBI-led advisory says

A joint FBI-led advisory says North Korean WaterPlum actors used fake technical interviews and coding tests to infect at least 30,000 devices in more than 100 countries.

25 Sept 2026 5 min
https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026

Threat Analysis

### Blockchain dead drops surge 440% as North Korea and Iran hide malware on public ledgers

Chainalysis research shows malicious blockchain writes rising from 2.06 to 11.1 a day in under a year, with state-linked groups now behind most new activity. Attackers are using ledgers that cannot be taken down to keep compromised machines connected.

24 Sept 2026 3 min
https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026

Artificial Intelligence

### OpenAI agent hacked Australian government Medicare portal, prime minister reveals

An autonomous OpenAI agent gained unauthorised access to an Australian government Medicare statistics portal in June, accessing public and non-public files. The government says it was not told until September, and a forensic investigation is under way.

24 Sept 2026 4 min
https://fire-vault.com/news/openai-agent-medicare-portal-breach-australia-2026

Breach Analysis

### FBI investigates claims that hackers stole personnel and applicant data

The FBI is investigating unauthorised activity affecting its recruitment website after ShinyHunters claimed it stole sensitive records on current and former personnel and job applicants. The claimed scale remains unconfirmed.

22 Sept 2026 4 min
https://fire-vault.com/news/fbi-employee-applicant-data-breach-shinyhunters-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers#webpage",
    "url": "https://fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers",
    "name": "South Korea fines Coupang $400m over data breac…",
    "description": "South Korea has issued its largest-ever data breach fine, penalising e-commerce giant Coupang more than $400m after the personal data of 37.5 million…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/news/south-korea-coupang-breach-hero.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "South Korea fines Coupang $400m over data breach affecting 37.5 million customers",
        "item": "https://fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "South Korea fines Coupang $400m over data breach affecting 37.5 million customers",
    "description": "South Korea has issued its largest-ever data breach fine, penalising e-commerce giant Coupang more than $400m after the personal data of 37.5 million customers, more than half the country's population, was exposed.",
    "url": "https://fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/south-korea-coupang-breach-hero.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/south-korea-coupang-breach-hero.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/news/south-korea-coupang-breach-hero.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/news/south-korea-coupang-breach-hero.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-06-14T15:21:39.800826+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/south-korea-fines-coupang-400m-data-breach-37m-customers"
    },
    "inLanguage": "en-GB",
    "articleSection": "News (Threat Analysis)",
    "wordCount": 810,
    "keywords": "South, News (Threat Analysis), data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "South Korea''s Personal Information Protection Commission (PIPC) has handed e-commerce giant Coupang a record fine of more than $400m (£299m) over a data breach that exposed the personal information of more than 37.5 million customers. It is the largest data breach penalty ever issued by the regulator, and a stark warning to any organisation holding population-scale customer data inside live, inte",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  }
]
```