South Korea’s Personal Information Protection Commission fined Coupang 625 billion won, about $422 million, at its June plenary session, the largest privacy penalty the commission has ever imposed. Regulators tied the number to a November 2025 breach that exposed names, emails, phone numbers, addresses and order histories across Coupang’s entire customer base.
Washington isn’t buying Seoul’s line that the fine “would be the same for any company.” American lawmakers say the move raises questions about whether South Korea is treating U.S. companies fairly, and a State Department spokesperson said Seoul “should not impose disproportionate burdens on U.S. companies.” Ambassador Kang Kyung-wha flew home to manage the fallout, calling the dispute “dragging on much longer than I expected.”
Coupang is fighting a second front at home. In the Northern District of California, a securities class action, Barry v. Coupang, alleges the company violated the Exchange Act by understating cybersecurity risk in filings covering purchases made between Aug. 6 and Dec. 16, 2025.
That’s the structural bind here. One government is punishing Coupang for weak security. Coupang’s own shareholders are suing it in a different country for how it described that same weakness beforehand. No single forum has to reconcile the two records, so the company answers to both at once, on different facts, in different languages.
Coupang says it wants a “constructive resolution” with Seoul. It hasn’t said the same about the California case, still in its early motions.
James Okafor