The Coupang data breach exposed the personal information of roughly 33.7 million customers — nearly the South Korean e-commerce company’s entire user base — after a former employee used cryptographic signing keys that had never been revoked to access internal systems from overseas between June and November 2025. South Korea’s data protection regulator has since imposed a record $409 million fine, Coupang has pledged more than $1 billion in customer vouchers, and consumer and investor lawsuits are pending in the United States and South Korea. As of mid-2026, no lawsuit has settled.
What Happened
Unauthorized access began on June 24, 2025, and continued undetected for nearly five months. South Korean police identified the perpetrator as a 43-year-old Chinese national who had worked at Coupang from November 2022 until 2024. After leaving the company, the individual kept cryptographic signing keys that were never revoked and used them to authenticate to Coupang’s internal systems from overseas servers.
Coupang noticed unusual access patterns on November 14, 2025, and confirmed the intrusion internally by November 18. It notified South Korea’s Internet and Security Agency, the Personal Information Protection Commission (PIPC), and the National Police Agency the same day. A public announcement followed on November 29, 2025.
The exposed data included customer names, phone numbers, email addresses, physical delivery addresses, and order histories. Coupang confirmed that payment card information, banking data, and login passwords were not compromised. The former employee reportedly retained data from about 3,000 accounts, which was later deleted after the breach became public.
Coupang’s Korean CEO Park Dae-jun resigned on December 10, 2025. “I feel a deep sense of responsibility for the outbreak and the subsequent recovery process, and I have decided to step down from all positions,” Park said. Harold Rogers, Coupang Inc.’s chief administrative officer and general counsel, was appointed interim CEO of the Korean subsidiary.1CNBC. CEO of South Korean Online Retail Giant Coupang Resigns Over Data Breach Founder and global CEO Bom Kim issued a public apology on February 27, 2026, saying the company’s priority was “earning customer trust.”2Korea Economic Institute of America. The Coupang Data Breach: A Timeline
The Record $409 Million Fine
On June 12, 2026, South Korea’s Personal Information Protection Commission announced the largest data-protection penalty in the country’s history: 624.7 billion won, approximately $409 million.3The Record. South Korea Data Breach Record Fine Coupang The penalty has two parts.
The first, roughly 423.5 billion won (about $278 million), is for the breach itself. The PIPC concluded it resulted from “deficiencies in basic safety management,” including poor management of authentication signing keys and access controls.4Wall Street Journal. South Korea Fines Coupang $410 Million Over Data Breach The regulator also found Coupang had failed to notify non-member victims despite being formally urged to do so four times in December 2025 and January 2026.3The Record. South Korea Data Breach Record Fine Coupang
The second, 201.1 billion won (about $132 million), addresses a separate violation: the unauthorized collection of third-party browsing data from 11.17 million users through the “Coupang Partners” affiliate marketing program. The program had been collecting website and app visit histories, URLs, access times, IP addresses, device identifiers, and other technical data from third-party platforms displaying Coupang advertisements, without proper user consent. The collection ran from December 23, 2024, to February 4, 2026.5The Lec. Coupang Partners Unauthorized Data Collection Fine The PIPC rejected Coupang’s argument that the data was “unintentionally gathered,” concluding it could not have accumulated without “deliberate system design.”6Pulse by Maeil Business Newspaper. Coupang Partners Data Collection PIPC Findings
A subsidiary, Coupang Fulfillment Services, received a separate fine of 248 million won for unlawful data collection and use, including placing journalists on an “employment-restriction list” and misusing employee health data during litigation.7Insurance Journal. South Korea Fines Coupang Record Amount Over Data Breach
The PIPC also found that Coupang manually deleted approximately six months of web access logs after regulators had ordered their preservation on November 21, 2025, and referred the company for criminal prosecution over the destruction of evidence. The commission separately ruled that Coupang had excluded its chief privacy officer from the internal investigation, calling it a “substantive violation of the legally mandated independence of the chief privacy officer’s role.”3The Record. South Korea Data Breach Record Fine Coupang
Coupang disclosed the penalty in a U.S. SEC 8-K filing and said it intends to challenge the fine in Seoul Administrative Court. The fines are not automatically stayed during appeals, so the company may have to pay while the challenge proceeds.8Stock Titan. Coupang Inc. Reports Material Event The total represents roughly 1.2% of Coupang’s 2025 revenue of $34.53 billion, well within the PIPC’s statutory ceiling of 3% of annual sales.7Insurance Journal. South Korea Fines Coupang Record Amount Over Data Breach
The $1 Billion Voucher Program for Affected Customers
In late December 2025, Coupang announced a compensation plan valued at approximately 1.685 trillion won (over $1 billion). Each affected user is eligible for a voucher worth up to 50,000 won (about $35), usable across Coupang’s shopping platform, food delivery service, travel offerings, and luxury beauty unit.9Yahoo Finance. Coupang Unveils Over $1 Billion Compensation Plan Eligibility extends to roughly 34 million users, including former customers who closed their accounts after the breach. Eligibility checks opened on January 15, 2026.10CNBC. Coupang Data Breach Compensation Vouchers
The vouchers drew criticism because they are usable only within Coupang’s own services, funneling the compensation back to the company. By mid-2026, Coupang reported recovering approximately 80% of lost members through the program.11Intellectia.ai. Coupang Shares Surge Following Privacy Fine Resolution
U.S. Lawsuits
Consumer Class Action in New York
In February 2026, a consumer class action was filed in the U.S. District Court for the Eastern District of New York. Named plaintiffs Cheol Hee Lee and Sebastian Park, both U.S. citizens, brought the case along with a subclass of more than 7,800 South Korean Coupang users. The suit, filed by SJKP Law Firm LLP (the U.S. affiliate of South Korea’s Daeryun Law Firm), names Coupang Inc. and Chairman Bom Kim and seeks $5 million in damages, alleging the defendants failed to meet their duty to protect customer information and cut costs that should have gone toward cybersecurity infrastructure.12UPI. Coupang Personal Data Breach Lawsuit Claims include negligence, implied contract violations, and violations of New York State’s consumer protection law.13Maeil Business Newspaper. Coupang Class Action Lawsuit Details
Coupang retained Kirkland & Ellis. As of late May 2026, the case was still in its early stages. An initial conference before U.S. District Judge Ann M. Donnelly was scheduled for June 17, 2026, to set the discovery timetable, and Coupang’s deadline to answer was July 6, 2026. Class certification remains contested.12UPI. Coupang Personal Data Breach Lawsuit
Securities Fraud Class Actions
Investors filed securities fraud class actions against Coupang, founder Bom Kim, and CFO Gaurav Anand. The core allegation is that the company misled investors about its cybersecurity posture and failed to disclose the ongoing breach in a timely manner as required by SEC rules, which mandate disclosure of material cybersecurity incidents within four business days of a materiality determination.
At least two related cases were filed. Barry v. Coupang, Inc. (No. 5:25-cv-10795) was brought in the U.S. District Court for the Northern District of California.14ZLK. Coupang Securities Class Action Lawsuit Update Hakrae Lee, et al. v. Coupang, Inc., et al. (No. 2:26-cv-00047) was filed in the U.S. District Court for the Western District of Washington. Both assert claims under Sections 10(b) and 20(a) of the Securities Exchange Act of 1934 and SEC Rule 10b-5. The expanded class period runs from May 7 through December 16, 2025, and the lead plaintiff deadline was February 17, 2026.15Saxena White. Saxena White Files Securities Fraud Class Action Against Coupang
According to the complaints, Coupang’s stock lost more than 25% of its value during the relevant period, with a 5.36% drop between November 29 and December 1, 2025 after the initial breach disclosure, a 3.2% decline on December 10 when CEO Park resigned, and a further 2% decline on December 16–17 when the full scope was confirmed.15Saxena White. Saxena White Files Securities Fraud Class Action Against Coupang No settlement has been reached, and motions to dismiss are expected.
South Korean Lawsuits and Mediation
In South Korea, approximately 240,000 victims filed a damages lawsuit in Seoul Central District Court on December 18, 2025. They initially demanded 100,000 won (about $68) per person, with plans to raise the claim to 300,000 won per person, a potential total of 72 billion won.16Korea Herald. 240,000 Victims of Coupang Data Leak Sue Company The filing followed public frustration with Coupang executives’ testimony at parliamentary hearings.17The Straits Times. 240,000 Victims of Coupang Data Leak Sue South Korean Company
The Personal Information Dispute Mediation Committee, a body operating under the PIPC, launched class mediation proceedings in parallel. Two separate applications (one from 50 claimants, another from more than 1,600) were consolidated into a single case. The proceedings were suspended on February 9, 2026, while the PIPC completed its administrative inquiry, then resumed on June 12, 2026. The committee is accepting additional applications through late October 2026 and intends to issue a mediation proposal within 60 days of that deadline. If either side rejects the proposal, the mediation is deemed to have failed.18Seoul Economic Daily. Korea’s Privacy Dispute Panel Resumes Coupang Class
The Suspect
On December 8, 2025, a South Korean court approved an arrest warrant for the 43-year-old Chinese national identified as the perpetrator. Prosecutors requested cooperation from Interpol and filed an extradition request with Beijing, but as of early 2026, China had not responded.19Yonhap News Agency. Court Approves Arrest Warrant for Coupang Breach Suspect The commissioner of the Seoul Metropolitan Police Agency acknowledged publicly that the investigation faces “limitations because the suspect is a foreign national” and that Interpol lacks enforcement power.20The Straits Times. Police Review Possible Arrest Warrant for Coupang’s Interim CEO Over Data Leak A smashed laptop the suspect had used was recovered, and the investigation continues.
Where Things Stand
Several threads remain open. Coupang plans to challenge the $409 million fine in Seoul Administrative Court, with no automatic stay of payment while it does. The consumer class action in the Eastern District of New York and the securities cases in California and Washington are all in early stages, with no settlements. The Korean mediation is accepting applications through late October 2026, and criminal referrals over the destruction of access logs are pending. The suspect remains outside South Korean custody.