Song Kyung-hee (second from left), chair of the Personal Information Protection Commission, holds a briefing on the sanctions resolution over the Coupang case at the Government Complex Seoul on the 11th. Yonhap News - Seoul Economic Daily Technology News from South KoreaSong Kyung-hee (second from left), chair of the Personal Information Protection Commission, holds a briefing on the sanctions resolution over the Coupang case at the Government Complex Seoul on the 11th. Yonhap News

The government’s imposition of a record-sized fine on Coupang, which suffered the hacking of 37.55 million people’s personal information, reflects the fact that it is an online platform used by the vast majority of the population. In particular, the move came because Coupang’s comprehensive failures were confirmed — not only the astronomical scale of the data leak but also its weak preemptive safety management system and unlawful post-incident handling. The Personal Information Protection Commission (PIPC) judged the gravity of this case to be very significant, given that the damage could grow further and that the leaked information is highly likely to be exploited in cybercrime.

null - Seoul Economic Daily Technology News from South Korea

Song Kyung-hee, chairperson of the PIPC, held a briefing at the Government Complex Seoul on Thursday and said, “We have decided to impose a total of 624.681 billion won in fines and 16.8 million won in penalties on Coupang Inc. for its violations of personal information protection laws, and resolved to issue corrective orders and disclosure orders.” The deliberation meeting held the previous day proceeded fiercely for 13 hours, the longest in the PIPC’s history.

The record-level fine was levied in this hacking incident because the unprecedented scale of the leak was reflected alongside the revenue scale of Coupang, which has grown into a “distribution giant.” The investigation found that the personal information leaked from Coupang between April and November last year totaled 37.56 million people, including 33.22 million members and 4.34 million non-members. This is 14 million more than the previous record leak by SK Telecom (23.24 million people).

The legal provision allowing for the imposition of “up to 3% of the average revenue over the three years preceding the incident” was applied in calculating the fine. Coupang’s average revenue during that period reached approximately 36 trillion won, but in calculating this fine, independent revenue with no direct or indirect connection to the violations (revenue related to business-to-business (B2B) operations such as Coupang Play and Coupang Eats) was excluded. Accordingly, the total fine calculated corresponds to 1.8% of the relevant revenue. Compared with the 0.8% fine ratio previously imposed on SK Telecom, this amounts to a weighting more than double.

The fact that Coupang has become an irreplaceable living infrastructure, and thus should have held a stricter sense of responsibility for security management, also served as a factor that raised the level of sanctions. Yang Cheong-sam, secretary general of the PIPC, explained, “Coupang is a platform used by the vast majority of our economically active population,” adding, “If the hacker’s claims are true, as much as 120 million pieces of address information were being managed, so the impact on the daily lives of the public is very large.”

The PIPC heavily reflected as aggravating factors not only Coupang’s violations themselves but also the uncooperative attitude it showed during the investigation and the possibility of expanded damage. Authorities judged this incident to be a “man-made disaster” that occurred due to an inadequate basic safety management system, rather than one resulting from advanced hacking techniques. The investigation found that Coupang poorly managed the digital signature key used for server authentication, which provided the opening for the hacker, a former employee, to freely access member information pages and the like.

Signs of evidence tampering were also detected during the investigation. Despite receiving an order to “preserve evidentiary materials such as incident-related access records” immediately after the PIPC launched its investigation, Coupang manually deleted about five months’ worth of web access logs. This made it very difficult to confirm the exact scope of damage. Yang said, “An analysis of the hacker’s threatening emails showed signs that more information was leaked than the officially announced scale,” pointing out that “the possibility of it being exploited in actual cybercrime down the road still remains.”

The PIPC also judged that the act of collecting users’ online activity records without authorization carried a strong element of illegality. Coupang was found to have collected and stored, without authorization, information on 15,645,338 web pages (URLs) and app usage visited by a total of 11,170,613 users from December 2024 to February this year.

Coupang was also found to have turned a blind eye to so-called “hijacking ads,” in which some advertising partners forcibly redirected users to Coupang’s web or app regardless of the users’ intent. Coupang Fulfillment Services (CFS), Coupang’s logistics subsidiary, also collected the personal information of 71 reporters covering the National Police Agency who had no record of working at logistics centers, citing “spreading false information,” and registered them on an employment restriction list (blacklist).

The PIPC plans to file a complaint with the police regarding Coupang’s obstruction of the investigation going forward. Meanwhile, regarding Coupang’s announcement that it would take legal action in defiance of this disposition, Song stressed, “This disposition is a decision made after deep deliberation in accordance with law and principle,” adding, “If a lawsuit is filed in the future, we will respond actively.”