Major Data Breach at Coupang Sparks National Outcry and Probes
South Korean authorities are investigating e-commerce giant Coupang following a significant data breach that exposed the personal information of millions of customers. The incident has drawn sharp criticism from the country's leadership and raised serious questions about corporate data security.
The breach, which occurred due to an internal system error, allowed users to see other customers' private data, including names, delivery addresses, and partial phone numbers, for approximately three hours on March 4 [36731]. Coupang stated that no financial data or full account passwords were compromised [36731]. However, the scale is vast; reports indicate the personal data of up to 33.7 million customers—nearly two-thirds of South Korea's population—was affected [32612].
President Lee Jae-myung has demanded immediate action, criticizing the company for its slow response. He labeled the damage "massive" and ordered a thorough government investigation to assign liability and ensure strong penalties [16765]. The national privacy watchdog, the Personal Information Protection Commission (PIPC), has launched its own probe. It is examining whether Coupang violated the Personal Information Protection Act, noting the company failed to report the incident within the legally mandated 72-hour window [21272].
In response to the breach, Coupang has apologized and is providing a 10,000 won (about $7.50) credit to every user who logged in during the error period [36731]. The company attributed the leak to a mistake during a routine service update [21272].
This incident has intensified scrutiny of major technology firms' data practices in South Korea, which has strict data protection regulations. The breach at the country's dominant online retailer, often called "the Amazon of South Korea," represents a major test of those rules and corporate accountability [21272].