
Flags of the United States, China, and South Korea, reflecting the geopolitical and regulatory tensions shaping foreign investment and trade in the region.
Shutterstock
Data breaches are common in a digital economy. The 2017 hack of Equifax exposed the private data of roughly 40% of Americans. A Yahoo breach of 3 billion accounts went unreported for years. Big attacks have hit Microsoft, Facebook, AT&T, and Bank of America – and even South Korea’s SK Telecom.
Against that backdrop, the breach at online retail company Coupang last year was relatively modest.
Coupang is a U.S. technology firm headquartered in Seattle and listed on the New York Stock Exchange. With $35 billion in revenues in 2025, it ranks 132nd on the Fortune 500 list just 15 years after launch with significant consumer-facing operations in the Asia Pacific region including Korea.
In November 2025 an unauthorized actor whom the company later identified as a Chinese former employee accessed approximately 33 million customer accounts but, according to a filing on behalf of U.S. investors in Coupang, “downloaded and retained data from only approximately 3,000 accounts,” all of which was fully recovered. By any objective measure, this was a manageable cybersecurity incident.
South Korea’s response has been anything but.
Offices were raided, at least 11 Korean agencies took punitive action, and there were “criminal charges lobbed against company executives, some of whom are U.S. citizens,” according to reports. The Prime Minister urged regulators to treat the company “with the same determination used to wipe out mafias.”
That reaction would be striking under any circumstances. It is even more so given what has happened since.
On April 29, South Korea’s Korea Fair Trade Commission moved to designate Coupang’s founder, a U.S. citizen based in the United States, as the company’s “same person,” or “controlling entity,” under Korean law. That designation carries significant legal consequences: it would subject him personally to Korean regulatory oversight, disclosure requirements, and potential civil and criminal liability.
This is not how cross-border investment is supposed to work.
As a U.S. company, Coupang is already regulated by U.S. authorities. Some 91% of the shares are owned by institutions like Blackrock and Vanguard.
Yet this proposed “same person” designation would effectively extend Korean jurisdiction beyond domestic operations to the leadership of a U.S. parent company.
The implications go well beyond one firm.
Under Korea’s Monopoly Regulation and Fair Trade Act, a “same person” must disclose all affiliated entities and governance relationships. For a multi-national like Coupang, that could expose board members, investors, and related entities to Korean regulatory scrutiny.
As one researcher told The Korea Times, this “amounts to the extraterritorial application of Korean regulations,” raising concerns about conflicts with existing trade commitments.
The U.S.-South Korea free trade agreement is meant to ensure non-discriminatory treatment of investors, grounded in the basic premise that countries regulate activity within their borders; they don’t regulate the internal governance of foreign firms. When that line begins to blur, investment decisions change quickly.
The U.S. Department of State’s most recent Investment Climate Statement already describes South Korea’s regulatory environment as “complicated” and “opaque.”
The Coupang case suggests something more troubling: that regulatory boundaries themselves may be shifting.
Those concerns intensified this week. South Korea’s privacy regulator imposed a record total of 624.7 billion won ($409 million) in fines against Coupang, $278 million of which is related to the data incident, and approximately $132 million is tied to a third-party advertising program. In total, this is the largest penalty of its kind in Korea’s history and four times the amount levied against domestic giant SK Telecom for a much more serious breach that involved exposing sensitive personal information of millions of users. Coupang has signaled that it will appeal. Whatever the outcome, the unprecedented scale of the sanction is likely to reinforce perceptions among foreign investors that regulatory risk in South Korea is becoming more difficult to assess.
Investors tend to notice patterns: a U.S. company faces a contained data breach, cooperates fully, and recovers. Yet it still encounters sweeping enforcement followed by a move that could extend jurisdiction over its U.S.-based leadership.
That signal is already influencing behavior. Reports suggest that regulatory concerns have complicated the planned U.S. listing of Toss, one of Korea’s most valuable fintech firms.
The implication is hard to ignore: if a high-profile, U.S.-listed company can face expanding regulatory exposure beyond its home jurisdiction, others may as well.
South Korea’s success as a dynamic, export-driven economy has long depended on attracting foreign capital and integrating into global markets. Maintaining that position requires clear, consistent rules anchored within well-understood jurisdictional boundaries.
If the goal is to strengthen the economy and maintain investor confidence, policymakers should reconsider the trajectory they are on. Otherwise, the message to global investors will be difficult to misinterpret.
There are many places in the world to invest. Increasingly, South Korea is making the case against itself.