Coupang Rejected a ₩100,000 Data-Breach Payout — But 33.7 Million Customers Could Still Take the Fight to Court

Business

Coupang Rejected a ₩100,000 Data-Breach Payout — But 33.7 Million Customers Could Still Take the Fight to Court

SEOUL — Coupang has rejected a South Korean consumer mediation proposal that would have paid ₩100,000 to customers seeking damages over one of the country’s largest personal-data breaches, choosing instead to leave additional compensation claims to the courts.

The e-commerce giant told the Korea Consumer Agency’s Consumer Dispute Mediation Committee in writing on September 11 that it would not accept the recommendation.

Coupang said it had reviewed the proposal carefully but concluded acceptance would be difficult after considering measures it had already taken and the wider implications of accepting the settlement.

The immediate case concerns only 50 consumers.

But that small number hides the enormous financial stakes.

The mediation committee had concluded in July that Coupang should pay each applicant ₩100,000 in cash or Coupang Cash for emotional distress arising from the breach. If Coupang had accepted the collective mediation and equivalent relief had ultimately been extended across the 33.7 million affected customer accounts originally identified by the company, the theoretical payout would have reached roughly ₩3.37 trillion.

Coupang chose not to take that route.

Why ₩100,000 became such a big number

On its face, ₩100,000—roughly US$70 to US$75—is relatively modest compensation for one customer.

Multiply it by tens of millions and the calculation changes dramatically.

Coupang originally disclosed that approximately 33.7 million customer accounts had been affected by the 2025 incident, representing a huge share of its Korean customer base.

At ₩100,000 each, that would equal approximately:

₩3.37 trillion.

That is why the mediation dispute is not simply about 50 people seeking several million won collectively.

Accepting the principle behind their claims could have created a much larger compensation precedent.

The mediation ruling was not a court judgment

This distinction is crucial.

The Consumer Dispute Mediation Committee found that Coupang should compensate the 50 applicants and became the first Korean dispute-mediation body to formally recognise the company’s liability for damages arising from the breach.

But the recommendation was not automatically binding on Coupang.

Under the mediation framework, the result would have taken on the effect of a court settlement if both sides accepted it. Coupang rejected it instead.

That means the decision does not by itself force Coupang to write cheques to 33.7 million customers.

Consumers seeking additional compensation may now have to pursue their claims through civil litigation.

Why the committee thought compensation was justified

The committee’s reasoning went beyond the simple fact that names and email addresses had been exposed.

It pointed to the sensitivity of some of the information involved.

According to the Korea Consumer Agency and subsequent reporting, compromised data included ordinary identifying information such as:

names,

email addresses,

home or delivery addresses,

and in some cases order histories and building or apartment entrance passwords.

The committee concluded that the nature of the information, the period over which unauthorised access occurred and uncertainty over potential misuse justified compensation for emotional distress.

That was an important finding because it treated the harm from a privacy breach as extending beyond proven financial theft.

Coupang says there is no confirmed secondary damage

Coupang strongly disputes the implication that the scale of accessed data translates into widespread actual misuse.

The company says independent forensic work found no confirmed case in which information from the incident was exploited for secondary harm.

It says the former employee responsible retained data from only about 3,000 customer accounts, later deleted that material and did not transfer it to third parties. Coupang has also said that 2,609 of those retained records contained building-access codes.

Coupang also says no banking details, payment-card information, account passwords or government-issued identification numbers were compromised. Its U.S. securities filings state that the incident involved names, phone numbers, delivery addresses, email addresses and certain order histories.

That is the company’s position.

Regulators reached a much harsher conclusion about how the breach was allowed to occur.

The government says the breach was bigger than Coupang’s original customer count

The Personal Information Protection Commission’s June investigation concluded that personal information connected to approximately 37.55 million people had been exposed.

That figure is larger than Coupang’s original 33.7-million-customer estimate because it includes people who were not necessarily registered Coupang members themselves.

The regulator broke the figure down into approximately:

33.22 million Coupang users, plus

4.33 million third-party data subjects, including people whose names, telephone numbers, addresses or other delivery information had been entered by Coupang customers.

For example, a customer might have ordered an item for a parent, friend or colleague and saved that person’s address.

The recipient could therefore have information in Coupang’s systems without maintaining their own Coupang account.

That explains why 33.7 million affected accounts and 37.55 million affected people can both appear in reporting without necessarily contradicting each other.

Regulators blamed basic security failures, not an elite hacking operation

Perhaps the most damaging government finding concerned how the breach happened.

The PIPC said its investigation concluded the incident resulted from inadequate basic security management rather than sophisticated hacking techniques.

According to the regulator, a former employee was able to exploit weaknesses involving authentication signing keys.

The PIPC found that Coupang had failed to manage those keys securely, did not promptly renew or destroy relevant credentials after the employee left and lacked adequate access-control measures to stop abnormal activity.

The unauthorised activity continued from April through November 2025.

The regulator said suspicious traffic had been generated during the period, but Coupang did not have sufficient thresholds and monitoring procedures in place to stop the access earlier.

That finding transformed the incident from a story about one rogue former worker into a broader argument over Coupang’s internal controls.

The government imposed a record ₩624.681 billion penalty

In June, the PIPC imposed ₩624.681 billion in penalty surcharges on Coupang along with a ₩16.8 million administrative fine and corrective orders.

It was the largest privacy-related financial sanction imposed by the regulator to date.

But another accuracy distinction matters here.

The entire ₩624.681 billion was not exclusively punishment for the breach itself.

Regulators also penalised Coupang for separate privacy violations, including the unauthorised collection of online activity records linked to about 11.17 million users visiting outside websites and apps displaying Coupang-related advertising.

Reporting on the regulator’s calculation put approximately ₩423.6 billion of the sanction in connection with the data-breach violations, while another roughly ₩201.1 billion related to unauthorised collection of users’ activity information.

Coupang has said some of its explanations and remedial actions were not adequately reflected in the regulator’s decision and has indicated it intends to pursue available legal procedures.

Coupang had already offered ₩50,000 per affected customer

The company’s main argument against another large compensation programme is that it has already launched one.

In December 2025, Coupang announced a package worth approximately ₩1.685 trillion, providing up to ₩50,000 in vouchers to each of about 33.7 million notified customers.

Distribution began in January.

But the ₩50,000 was not simply cash that customers could spend anywhere.

The package was divided among several Coupang-related services.

Customers received:

₩5,000 for Coupang’s main e-commerce platform,

₩5,000 for Coupang Eats,

₩20,000 for travel products,

and ₩20,000 for R.LUX luxury beauty and fashion items.

That structure immediately became controversial.

Critics said the compensation doubled as marketing

Consumer groups argued that vouchers usable only within Coupang’s ecosystem were fundamentally different from cash damages.

The compensation required consumers to return to Coupang or affiliated services to extract much of the stated value.

Critics therefore described the programme as potentially functioning partly as a sales or customer-retention tool rather than straightforward financial redress.

The company has defended the programme as a substantial voluntary measure.

At its headline maximum value, ₩50,000 across 33.7 million recipients equals approximately ₩1.685 trillion.

That is a huge announced package.

But the economic cost to Coupang ultimately depends partly on how many vouchers are redeemed and which products customers purchase.

Coupang’s U.S. filings say the vouchers are recognised as reductions to selling prices and revenue as customers redeem them.

The rejected mediation was potentially twice as large

The contrast is striking.

Coupang’s voluntary voucher programme carries a headline value of around:

₩1.685 trillion.

A ₩100,000 payment across 33.7 million customers would imply:

₩3.37 trillion.

So the mediation framework potentially represented roughly twice the headline value of Coupang’s existing compensation offer.

That helps explain why the company referred to the wider ramifications of accepting the proposal.

Acceptance could have been interpreted not merely as settling with 50 applicants but as endorsing a much larger standard for damages.

Civil groups say the dispute is now heading toward courtrooms

Civic organisations reacted angrily to Coupang’s rejection.

A coalition including People’s Solidarity for Participatory Democracy argued that the company was effectively forcing customers to litigate over additional compensation rather than resolving the issue through mediation.

The groups have also renewed calls for stronger collective-redress mechanisms in South Korea.

Their argument is that requiring millions of individuals to pursue separate civil actions makes compensation difficult even when a mass breach affects an enormous population.

That is an advocacy position, not a legal ruling.

Coupang, meanwhile, retains the right to contest both liability and the amount of any damages claimed in court.

The absence of confirmed fraud does not automatically erase privacy harm

One of the most important arguments likely to surface in future litigation is the meaning of “damage.”

Coupang emphasizes that it has identified no confirmed secondary misuse attributable to the breach.

That is significant.

If customers had suffered bank theft, identity fraud or documented physical harm, claims for direct losses could be much easier to quantify.

But the Consumer Dispute Mediation Committee’s finding was based partly on a different concept:

emotional distress and privacy loss can themselves constitute damage.

That is why the absence of proven financial fraud did not prevent the committee from recommending compensation.

Whether courts reach similar conclusions—and at what amount—is a separate question.

Building-access codes make this case particularly sensitive

The presence of building or apartment entrance codes made the breach more alarming than a conventional database exposure involving only emails.

Coupang says forensic analysis found 2,609 accounts with building lobby access codes among the roughly 3,000 records retained by the former employee.

The regulator’s broader investigation also identified building-access passwords among the types of third-party delivery information exposed through the affected systems.

That does not prove anyone used those codes to enter a building.

Coupang says no such secondary harm has been confirmed.

But the type of information itself increases privacy and physical-security concerns because it relates directly to where people live and how their buildings are accessed.

Order histories carry another kind of privacy risk

Order histories can reveal details about a person that are far more intimate than an email address.

Purchases can potentially expose:

medical concerns,

family circumstances,

personal interests,

travel activity,

children’s products,

household patterns,

or other aspects of private life.

The mediation committee specifically cited order-history information when explaining why emotional-distress damages were appropriate.

Again, that does not mean all 33.7 million affected accounts had every category of sensitive information exposed.

Different subsets contained different information.

That distinction should be preserved in responsible reporting.

Coupang discovered the incident in November 2025

According to Coupang’s filing with the U.S. Securities and Exchange Commission, the Korean business became aware of unauthorised access on November 18, 2025.

It reported the incident to Korean regulators and law enforcement, closed the method used for access and notified customers whose information might have been involved.

The company publicly announced the large-scale breach later that month.

Subsequent government investigations expanded the understood scope and examined whether Coupang had complied with notification, destruction and security obligations.

The PIPC eventually concluded that several legal duties had been violated.

Regulators also questioned Coupang’s response after the breach

The PIPC’s June ruling did not focus only on what happened before the data was accessed.

It also cited problems involving:

delayed notification,

personal-data destruction obligations,

the independence of Coupang’s chief privacy officer,

and alleged obstruction of the regulator’s investigation.

Coupang has disputed elements of the government’s findings and says the company’s own forensic investigation established a narrower picture of what information was actually retained or exploited.

That creates two different layers of the dispute.

One concerns how much information systems were accessed.

The other concerns what data the former employee actually retained, shared or misused.

Those questions are not identical.

The 33.7 million versus 37.55 million problem

For editors, this may be the most important statistical trap in the entire story.

You will see both numbers in credible reports:

33.7 million.

37.55 million.

They describe different things.

Coupang’s original compensation programme covered approximately 33.7 million customer accounts notified after the incident.

The privacy regulator later said its investigation found personal information associated with about 37.55 million people, because delivery information included millions of people who were not themselves Coupang members.

So a headline saying “37.55 million Coupang customers” would be inaccurate.

Likewise, calculating the ₩100,000 mediation exposure by multiplying 37.55 million without explaining the different group would overstate what the current consumer-mediation reporting actually describes.

For the disputed compensation plan, 33.7 million is the relevant headline population.

The biggest number is no longer the most important question

Coupang’s rejection makes ₩3.37 trillion an attention-grabbing figure.

But it is still a hypothetical exposure, not a bill the company has been ordered by a court to pay.

There is currently no final judgment requiring Coupang to compensate all 33.7 million customers ₩100,000 each.

The 50-person mediation failed because Coupang rejected it.

Additional claims can now move toward civil litigation.

Courts could reach different conclusions about liability, damages or eligibility.

And individual circumstances may differ.

That is why reporting this as “Coupang ordered to pay ₩3.37 trillion” would be wrong.

What happens next could matter far beyond Coupang

The eventual legal outcome may help define how South Korea treats mass digital-privacy harm.

Coupang is one of the country’s dominant digital-commerce platforms.

The breach affected data connected to a population equivalent to a substantial majority of South Korea.

The government has already imposed a record privacy penalty.

The consumer mediation body has already recognised emotional-distress liability for the 50 applicants.

Coupang has already launched a ₩1.685-trillion voucher programme.

And now it has rejected a settlement principle that could have exposed it to roughly twice that headline amount.

The next battle may therefore not be about cybersecurity technology at all.

It may be about something much more basic:

How much is the loss of personal privacy worth when tens of millions of people are affected at the same time?

Coupang’s answer, for now, is that its existing response should be enough to reject another blanket payout.

The Consumer Dispute Mediation Committee reached a different conclusion for the customers before it.

With mediation now rejected, the courts may be where those two positions finally collide.

Leave a Reply

Your email address will not be published. Required fields are marked *