South Korea’s Personal Information Protection Commission fined US-headquartered retail giant Coupang a record-breaking 624 billion won (over $400 million) on Thursday after a massive security breach compromised the personal data of more than 34 million customers.
How the “Amazon of Asia” Exposed Millions of Users
Often dubbed the “Amazon of Asia” due to its dominant market presence, the e-commerce titan operates predominantly in South Korea despite its corporate headquarters being located in the United States. Following the discovery of the security failure in December 2025, investigations revealed that the months-long breach allowed a former employee to illicitly harvest highly sensitive customer records. The compromised dataset included names, email addresses, physical shipping destinations, phone numbers, and detailed order histories, directly impacting approximately two-thirds of the South Korean population.
Geopolitical Tensions and Legal Appeals
In response to the historic penalty, Coupang confirmed to BBC News that it intends to legally challenge the regulator’s decision. This multi-million-dollar sanction represents an exceptionally rare instance of severe financial punishment imposed by South Korean authorities on a US-based enterprise. The case has also triggered diplomatic friction, with South Korean legislators accusing American politicians of attempting to exert undue political pressure. These allegations arose after reports surfaced that US representatives tried to link the domestic data breach investigation to broader US-South Korea bilateral relations in an effort to shield Coupang’s executive team.
The Regulatory Divide
This international dispute underscores a stark contrast in global privacy enforcement. US-based corporations rarely face comparable domestic financial penalties or criminal prosecutions following major data exposure incidents, a leniency largely attributed to the lack of comprehensive federal privacy legislation and limited regulatory enforcement powers within the United States.
