South Korean e-commerce operator Coupang Inc. swung to a second-quarter net loss of 865 billion won (about US$570 million), down from a 43.5 billion won net profit a year earlier, after booking the regulatory fines tied to its confirmed large-scale customer data breach, the company said in an August 5 earnings release reported by Yonhap News Agency. The charge stems from a record fine imposed in June by South Korea's Personal Information Protection Commission (PIPC), reported as 624.7 billion won by Yonhap, 624.68 billion won by the Korea JoongAng Daily, and rounded to 625 billion won (US$403 million) by AP. The underlying incident, disclosed in November 2025, is one of the largest consumer data compromises ever recorded in South Korea, with victim counts reported between roughly 33.7 million and 37.56 million people.
What Happened
The breach surfaced publicly in November 2025. According to the Korea JoongAng Daily, Coupang did not detect the intrusion through its own monitoring and instead learned of it from a customer complaint, a failure that drove much of the subsequent public anger in Korea. Coupang acknowledged the scale of the leak in December 2025.
From there the incident moved onto three separate tracks that are now converging on the company's balance sheet:
Regulatory. In June 2026 the PIPC levied its record fine over both the breach and, per Yonhap, the collection of users' online activity data without consent. On the earnings call, CFO Gaurav Anand said the Product Commerce segment results "include the fines recently imposed by Korean regulatory authorities," adding that "while these fines are still subject to judicial review and we plan to appeal them through the courts, we recorded the expenses this quarter."
Civil liability. On July 31, 2026, the Consumer Dispute Settlement Commission, operating under the state-run Korea Consumer Agency, ruled that Coupang must pay 100,000 won (reported as US$69 to US$70) per person to 50 consumers who filed a collective dispute mediation request on December 8, 2025. Multiple Korean outlets, including the Korea Herald, Korea Times, Seoul Economic Daily, Asia Business Daily and Korea JoongAng Daily, describe this as the first formal recognition of Coupang's liability for damages arising from the breach. The commission opened proceedings on April 6 and held two sessions, on July 10 and July 22. Coupang has 15 days from receipt to accept or object; absent an objection the proposal is deemed accepted and carries the same legal effect as a court-approved settlement.
Geopolitical. AP reports that a U.S. House Judiciary Committee report accused Seoul of discriminating against the U.S.-listed company. South Korea's Foreign Ministry spokesperson Park Il pushed back the following day, saying the report reflected "only Coupang's unilateral claims," omitted Seoul's position, and that the investigation and resulting measures were carried out under domestic law.
Accounts differ on the headline victim number. Yonhap cites "more than 37 million customers." The Korea Herald reports Coupang admitted in December 2025 to 33.7 million affected users, described as nearly its entire customer base, while a subsequent government probe put the figure as high as 37.56 million. Asia Business Daily uses 37.56 million. Korea JoongAng Daily refers to "around 34 million." The gap appears to be the difference between the company's own count and the regulator's, not a dispute over the facts of the intrusion.
What Was Taken
The exposed data set is what makes this breach unusually damaging relative to its size. Consistently across the Korean reporting, the leaked records included:
- Names
- Email addresses
- Home addresses
- Apartment shared entrance passcodes
- Order histories
The Consumer Dispute Settlement Commission specifically cited the entrance passcodes and order histories as information "closely tied to private life," and used that sensitivity as a basis for finding emotional distress damages. Home address plus building entry code is a physical-access combination, not merely an identity-theft one. Order history layered on top of that yields a behavioral profile: what a household buys, when, and how often.
The commission also found concrete evidence of misuse potential. Per the Korea Times and Seoul Economic Daily, data was siphoned over an extended window running from April to November 2025, and the attacker directly emailed some affected customers about the leak. Coupang argued to the commission that no further leaks were possible because it had recovered all the leaked personal information and the devices used in the crime; the commission ruled that this could not be established with certainty and declined to accept it.
Why It Matters
For defenders, the significant number in this brief is not 37 million. It is 865 billion won of net loss booked in a single quarter, against a business whose core Product Commerce segment posted $7.42 billion in revenue, up just 1 percent year over year.
Three things follow from that.
First, the regulatory penalty landed roughly seven months after disclosure and is large enough to invert quarterly profitability at a company of Coupang's scale. Breach cost modeling that stops at incident response, forensics, and notification is understating exposure by an order of magnitude in jurisdictions with an activist data protection regulator.
Second, the civil track compounds the regulatory one asymmetrically. The mediation ruling covers 50 applicants, an amount trivial in isolation. Asia Business Daily notes explicitly that extending full compensation to all 37.56 million leaked accounts would be a heavy burden. At 100,000 won per person, universal application would run to roughly 3.7 trillion won, several times the record fine. Whether that materializes depends on follow-on litigation, but the mediation ruling establishes the per-victim benchmark that future claims will anchor to, and the commission set it by reference to what Korean courts have historically awarded in large-scale breach cases.
Third, customer churn was not the primary financial damage. Coupang founder and Chairman Bom Kim said a majority of customers not only returned but resumed prior spending levels, and that customer spending excluding those who left and never came back rose 16 percent year over year. The company guided to 8 to 9 percent third-quarter revenue growth despite an unfavorable Chuseok holiday calendar shift. The lesson is uncomfortable but worth stating plainly: consumers largely forgave a breach of nearly the entire user base, while the regulator did not. Boards that model breach risk primarily as brand and retention risk are modeling the wrong variable.
The Attack Technique
Technical detail remains thin, and no primary incident report or vendor advisory is among the available sources. What the reporting supports:
The Korea JoongAng Daily attributes the breach to a former employee who leaked the personal information of around 34 million people. That insider attribution appears in a single outlet in this source set and should be treated as reported rather than independently confirmed. Other outlets in this set refer only to "the hacker" or "hackers" without characterizing the access path.
What multiple sources do agree on is the shape of the operation. Exfiltration ran from April through November 2025, an approximately seven-month dwell period, and Coupang did not identify it through internal detection. The attacker later contacted some victims by email directly. Coupang has told the commission it recovered the exfiltrated data and the devices used, which implies a law enforcement seizure or a recovery action against identified individuals rather than an anonymous external actor who remained at large.
A months-long, high-volume extraction of customer records that terminates only after an outside complaint is the signature of missing egress and access-anomaly monitoring rather than a sophisticated perimeter defeat. If the insider attribution holds, the failure was authorization scope and behavioral detection on legitimate credentials, which is exactly the case where perimeter controls contribute nothing.
What Organizations Should Do
-
Instrument for volumetric access anomalies on authorized accounts. A seven-month extraction window ending in an external tip means no threshold existed on how much customer data a valid account could read. Baseline per-identity record access rates against role norms, and alert on sustained deviation, not just on single large exports.
-
Treat departing and recently departed staff as a distinct revocation workflow. Where insider access is suspected, verify that credential revocation, API token invalidation, VPN, SSO session termination, and third-party tool access all complete on the same clock as HR offboarding. Audit for orphaned service accounts and personal API keys created during tenure.
-
Reclassify physical-access fields as high-sensitivity data. Apartment entrance passcodes, delivery instructions, gate codes, and building access notes are frequently stored in delivery platforms as free-text with the same protection as a phone number. Encrypt them separately, restrict read access to the narrow set of systems that need them at delivery time, and set aggressive retention expiry.
-
Minimize order history retention. The commission's damages reasoning leaned heavily on order history as privacy-invasive. Define a retention ceiling for line-item purchase records, tokenize or aggregate beyond it, and separate the analytics copy from the operational copy so a single compromise cannot yield both.
-
Verify consent scope for behavioral and activity data separately from breach controls. The PIPC fine covered both the breach and collection of user online activity without consent. Those are independent findings. Run a consent audit against every telemetry and tracking pipeline, and confirm the legal basis is documented per data category, not per product.
-
Model regulatory and civil exposure explicitly in breach risk planning. Build the financial scenario with three lines: regulatory penalty, per-victim civil compensation multiplied by full affected population, and remediation. In jurisdictions such as South Korea, the EU, and increasingly the U.S. states, the first two dominate. Ensure legal, finance, and security agree on the numbers before an incident, not during one.
Sources: (LEAD) Coupang swings to Q2 loss on data breach fines Yonhap News... | South Korea disputes US report claiming Coupang discrimination AP... | Coupang faces 100,000 won payout per victim over data breach - The... | Coupang ordered to pay data breach victims $70 each - The Korea Times | Consumer Dispute Panel Orders Coupang to Pay 100,000 Won for Data B... | Consumer Dispute Mediation Committee: "Coupang Must Compensate Data... | Coupang told to pay data breach damages in first ... | Coupang Ordered to Pay 100,000 Won Each Over 37.5 Million Data Brea...