South Korea imposes heavy fines on e-commerce company Kupeng over personal data leakage case, with record fine of 624.7 billion won
Quick Look
- South Korea’s Personal Information Protection Commission (PIPC) imposed a record-breaking fine of approximately 624.7 billion won on the e-commerce company Coupang due to the personal data leakage of nearly 37.5 million customers at the end of last year.
- PIPC pointed out that the leak was caused by a failure in Coolpeng's security management system rather than a complex hacker attack.
- The incident also triggered diplomatic friction between South Korea and the United States.
AI-generated summary
South Korean e-commerce company Coupang suffered a leak of personal information of nearly 37.5 million customers at the end of last year, and was heavily fined 624.7 billion won by South Korea. (Reuters)
[Compiled by Lu Yongshan/Comprehensive Report] "Bloomberg" reported that Coupang, a South Korean e-commerce giant listed in the United States, had the personal information of nearly 37.5 million customers leaked at the end of last year. South Korean personal information The Information Protection Commission (PIPC) said on the 11th that it would impose a record-breaking fine of approximately 624.7 billion won (NT$12.93 billion) on Cool Peng, a move that may increase diplomatic friction between South Korea and the United States.
The amount of PIPC's fine against Coolpeng will set a record for the largest fine imposed on a South Korean company for leaking customer personal information, surpassing the 134.8 billion won (NT$2.79 billion) fined by SK Telecom last year. According to South Korea's current regulations, PIPC can fine companies 3% of their annual revenue.
Kyung Hee Song, chairman of PIPC, said: "This incident was not caused by sophisticated hacking methods, but because of Coolpeng's inadequate basic security management system and negligent management. The company has grown rapidly by leveraging large-scale customer data to provide innovative e-commerce services, but the investigation found that its customer personal information protection and management system failed to keep pace."
PIPC determined that Coolpeng had negligence in its basic security management system, which resulted in the leakage of personal information of approximately 37.5 million customers (including approximately 205,000 people in Taiwan). During the investigation, it was also discovered that Kupeng violated its obligations to report and destroy personal information leakage, failed to protect the independence of the person in charge of personal information protection (CPO), and obstructed investigations.
After an investigation by South Korean regulators, it was discovered that a former employee of Coolpeng illegally accessed customer personal information from nearly 34 million accounts for several months without being noticed, making the company the target of criticism from all walks of life in South Korea. Domestic dissatisfaction with Kupeng in South Korea, coupled with official investigations into its cyber security, has led to diplomatic friction between South Korea and the United States.
After the personal information leakage of Coolpeng customers, Greenoaks Capital Partners, Coolpeng’s major shareholder, urged the U.S. government in January this year to investigate whether the South Korean government had discriminatory treatment against the e-commerce company listed in the United States. South Korean lawmakers are pushing back against U.S. political pressure on the country's government over its handling of Ku Peng and his top brass.
In response to the PIPC ruling, Coolpeng expressed regret, emphasizing that "the ruling does not fully reflect Coolpeng's active efforts to avoid secondary harm after the personal information leakage incident last year."
Grasp the economic pulse with one hand. Click here to subscribe to Free Finance Youtube Channel



