TL;DR: South Korea's Personal Information Protection Commission (PIPC) fined Coupang 624.6 billion won (about $409 million) on June 11, 2026, for a November 2025 breach that exposed the personal data of 37.55 million South Korean users, roughly the entire active user base of the country's biggest online retailer. The per-record math works out to $10.89 per person on the PIPC count, or $12.13 per person on Coupang's own November 2025 disclosure of 33.7 million compromised accounts. The 2017 Equifax settlement, the biggest US data-breach penalty of the last decade, worked out to $4.76 per person on the full $700 million, or $2.89 per person on the $425 million consumer-restitution fund. The 2018 Marriott settlement, the second biggest, was $123 million for 339 million records: $0.36 per record. The 2015 Anthem settlement was $115 million for 78.8 million records: $1.46 per record. South Korea's per-record fine on Coupang is more than double the full Equifax settlement, more than seven times the Equifax consumer fund, and roughly thirty times the Marriott penalty. The US has no federal privacy regulator with the authority to fine a single breach anywhere near this scale. The Federal Trade Commission has Section 5 authority, but the per-record math in its biggest settlements has never crossed $5. The Colorado, Connecticut, and California state privacy laws that took effect over the last 18 months have the civil-penalty structure to do better, but none has yet produced a single breach fine in the $100 million range.
What Happened on June 11
Coupang is the Amazon of South Korea. 95,000 employees, $30 billion in annual revenue, 33 million paying Wow members, 75 percent household reach. On June 11, 2026, the PIPC announced the fine. The regulator's finding: Coupang failed to maintain a basic security management system, including negligence in authentication key management and access controls, and the personal data of approximately 37.55 million people was leaked. The PIPC also cited violations of data destruction and notification requirements, interference with the independence of Coupang's data protection officer, and obstruction of the investigation.[1]
The fine: 624.681 billion won on the main safety-measure violation, plus 16.8 million won on a separate collection-without-legal-basis violation. A subsidiary, Coupang Fulfillment Service, was separately fined 248 million won for unlawfully collecting and using customer data. The PIPC also issued corrective orders, public announcements, and publication orders.[1] The math on the headline number: 624.6 billion won, at the June 11 exchange rate, is roughly $409 million. The Reuters and BleepingComputer coverage puts the dollar figure in the same range. The Korea Times and TechCrunch put it the same way.[1][2][3]
The breach itself was discovered in mid-November 2025. Coupang disclosed at the time that 33.7 million accounts had been compromised. The company announced in late December 2025 that it would pay 1.685 trillion won (about $1.17 billion) and distribute 50,000 won (about $34) per customer in single-use purchase vouchers to more than 33 million affected users, with payments starting in January 2026.[1] That compensation plan is the part the US press covered when it happened. The PIPC fine is the regulatory follow-up, and the regulatory follow-up is the part with the comparative math.
The primary suspect in the breach is a 43-year-old Chinese national who worked in Coupang's IT department between 2022 and 2024. According to South Korean authorities, the suspect retained multiple hard drives containing sensitive data, accessed millions of accounts (retaining user data for approximately 3,000), disposed of a MacBook Air in a river to destroy evidence, and was arrested after the device was recovered.[1] The breach was one of the worst in South Korean history. It sits alongside the SK Telecom USIM data exposure disclosed in April 2026, which infected SK's network starting in June 2022 and affected 27 million subscribers, essentially the carrier's entire customer base.[1]
The Per-Record Math: Why the US Numbers Are Embarrassing
The Coupang fine is $409 million. The 37.55 million people PIPC counted as affected is the official denominator. $409 million / 37.55 million = $10.89 per person. If you use Coupang's own November 2025 disclosure of 33.7 million compromised accounts, the per-record number is $409 million / 33.7 million = $12.13 per person. Either way, the Korean regulator put a price tag on a single data breach that is an order of magnitude higher than anything the US has produced in the last decade.
Here is the comparison. All numbers from primary sources (FTC press releases, court settlement documents, or the regulator's official order). All denominators from the official affected-population count at the time of settlement.
South Korea Coupang (June 2026): $409 million, 37.55 million people. $10.89 per person. The PIPC used existing statutory authority. No new law was required. The fine is roughly 4 percent of Coupang's annual revenue.[1][2][3]
US Equifax (2017 breach, 2019 settlement): $700 million total settlement, 147 million people affected. $4.76 per person on the full settlement. The consumer-restitution fund, the part that actually went to people, was $425 million. $2.89 per person on the consumer fund. The settlement was split among the FTC, the Consumer Financial Protection Bureau, and 50 states and territories.[4][5]
US Marriott (2018 Starwood breach, 2024 settlement): $123 million class-action settlement, 339 million guest records exposed. $0.36 per record. Marriott disclosed the breach in November 2018. The 339 million number includes 18.5 million passport numbers and 5.25 million unencrypted passport numbers. The settlement came after six years of class-action litigation.[6]
US Anthem (2015 breach, 2017 settlement): $115 million settlement, 78.8 million records. $1.46 per record. Anthem is the largest US health-insurance data breach on record. The settlement was $39 million below the statutory cap. The remaining $2 billion in exposure was held back by indemnification clauses with the company's cyber-insurance carrier.[7]
US Yahoo (2013-2014 breach, disclosed 2016): $350 million severance-credit reduction in the Verizon acquisition price, 3 billion accounts. $0.12 per record. The Yahoo fine was not even a fine. It was a price concession in an M&A deal, and it is still the largest per-record US settlement by total dollars, because the breach was the largest in history by accounts affected.[8]
The Korean regulator fined a single breach more than 2x the per-person cost of the US's biggest data-breach settlement on a full-settlement basis, and more than 7x the per-person cost on a consumer-fund basis. The math is not a close call. The US has not produced a single breach penalty that crosses $5 per person. South Korea just produced one that crosses $10 per person.
Why US Regulators Have Not Matched the Korean Enforcement
The structural reason is the FTC's authority. The FTC brings data-breach cases under Section 5 of the FTC Act, which prohibits "unfair or deceptive acts or practices in or affecting commerce." Section 5 gives the FTC the power to obtain redress for consumers and injunctions against future violations, but it does not give the FTC a clean civil-penalty authority for first-time data-security violations by a company that is not a financial institution or a credit reporting agency. The Gramm-Leach-Bliley Act and the Fair Credit Reporting Act give the FTC direct civil-penalty authority in narrow sectors. For everyone else, the FTC has to go to court and prove the violation was a "practice" that was "unfair" or "deceptive." The Equifax settlement, the FTC's biggest data-breach penalty to date, was structured as a redress fund plus injunctive relief plus state-AG parallel actions, not a civil penalty.[4][5]
The CFPB, the Consumer Financial Protection Bureau, has more direct civil-penalty authority inside the consumer-finance sector, and the Equifax settlement did pull a CFPB component. But the CFPB's data-breach authority is bounded by the consumer-finance perimeter. Most of the recent high-profile breaches (Marriott, Anthem, Yahoo, the 2024 Snowflake customer breaches, the 2025 Salesforce customer breaches, the 2026 PowerSchool breach) involve companies outside the consumer-finance perimeter.[4][5]
The SEC has brought some cybersecurity-disclosure cases under its 2023 cyber-disclosure rule, and the Department of Health and Human Services has the HIPAA right-of-action path. The HIPAA penalties are the closest US analog to the PIPC structure. The largest HIPAA settlement to date is the Anthem $115 million, which is also the US's second-largest data-breach fine. The 2018 Anthem settlement was negotiated with the Department of Health and Human Services Office for Civil Rights, and it was the largest HIPAA settlement in history. The per-record math is still $1.46.[7]
The result is a regulator patchwork that has never produced a single breach fine in the $400 million range. The closest US analog, the 2019 Facebook $5 billion FTC settlement, was a Section 5 case brought against Facebook for the Cambridge Analytica deception, not for a data breach. The largest US data-breach fine, the Equifax $700 million, was a redress fund plus state-AG coordination. The per-person cost to Equifax was the cost of running a legal department, not the cost of losing 147 million people's data.[4][5]
The Korean regulator had a different toolkit. The PIPC's authority comes from the Personal Information Protection Act, which was amended in 2022 to raise the maximum administrative fines. The PIPC can fine up to 3 percent of a violator's revenue for safety-measure violations, and up to 4 percent for collection-without-legal-basis violations. Coupang's 4 percent revenue exposure was the legal ceiling PIPC used. The US FTC has no equivalent revenue-proportional authority. State AGs do, under the new state privacy laws, but none has yet used it against a single breach at scale.[1][9]
The State AGs Are the Closest Thing the US Has to PIPC
Three state privacy laws passed in 2023-2024 created the first US civil-penalty structure for data breaches that is roughly comparable to the PIPC's authority.
Colorado Privacy Act (CPA): Effective July 2023. Enforcement began July 2024. The Colorado Attorney General has exclusive enforcement authority. Civil penalties up to $20,000 per violation under the Colorado Consumer Protection Act. The CPA's data-protection-assessment requirement is the first US analog to the GDPR's DPIA. As of June 2026, the Colorado AG has not yet announced a major data-breach civil penalty under the CPA, but several investigations are reportedly open.[10][11]
Connecticut Personal Data Privacy and Online Monitoring Act (CTDPA): Effective July 2023. The Connecticut AG has exclusive enforcement authority. Civil penalties up to $5,000 per violation, with the right to seek equitable relief and restitution. As of June 2026, the Connecticut AG has not yet announced a major data-breach civil penalty under the CTDPA, but a 2025 amendment expanded the law to cover neural data and AI training.[10][11]
California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA): The California Privacy Protection Agency has independent enforcement authority. The CCPA's civil-penalty structure is $2,500 per violation, or $7,500 per intentional violation or violation involving a minor. The CPPA's first major enforcement action was the September 2025 Tractor Supply Co. settlement, which included $1.4 million in total penalties for CCPA violations. The Tractor Supply settlement was the first CPPA enforcement action to use the per-violation structure. The dollar-per-violation math is the closest US analog to the PIPC's per-record structure. The 2026 California S.B. 2564 surveillance-pricing bill, currently moving through the legislature with EFF and Center for Democracy and Technology (CDT) support, would add a data-broker-registration civil-penalty structure on top.[10][11][12]
The per-violation math under CCPA is closer to the PIPC structure than the FTC's redress-fund model. The Tractor Supply settlement at $1.4 million on a CCPA-class violation pattern is still an order of magnitude below the PIPC's $409 million on a single breach, and CCPA's per-violation cap is $7,500, not a percentage of revenue. The PIPC's revenue-proportional authority is the structural piece the US state laws are missing. None of the 2023-2024 state laws includes a PIPC-equivalent revenue-percentage cap.[10][11][12]
The 2025 state wave has not changed this. Arkansas, Utah, Texas, Oregon, Montana, Delaware, Iowa, Indiana, Kentucky, Maryland (the Oct 1 deadline is the next milestone), New Hampshire, New Jersey, Rhode Island, Tennessee, and Virginia all passed or amended privacy laws in 2025-2026. The New York surveillance pricing ban, signed in May 2026, is the third state to ban the practice after Colorado and Connecticut. None of the 2025-2026 state laws has produced a single breach fine in the $100 million range, and none has revenue-proportional PIPC-style civil-penalty authority.[12][13]
The US Enforcement Gap Is Structural, Not Political
The conventional explanation for the US enforcement gap is that Congress will not pass a federal privacy law with a PIPC-equivalent civil-penalty structure. That explanation is true but incomplete. The American Privacy Rights Act (APRA) has been stalled in committee since 2024. The APRA's civil-penalty ceiling was $5,000 per violation, which would not have closed the PIPC gap even if it had passed. The state laws that have moved have moved within the same $5,000-per-violation range, with the CCPA's $7,500-per-violation maximum as the high water mark.[14]
The structural gap is not a per-violation number. It is the absence of a revenue-proportional civil-penalty ceiling. The PIPC can fine up to 4 percent of revenue. The FTC's per-violation maximum is bounded by what a court will accept under Section 5, and the courts have not been willing to accept per-violation math that crosses $5. State AGs have the per-violation math, but the per-violation caps are below $10,000 in every state law that has moved.
The result is a regulator structure that is structurally incapable of producing a PIPC-style fine. The PIPC's $409 million on Coupang is roughly 1.3 percent of Coupang's $30 billion annual revenue, well below the PIPC's 4 percent ceiling. The FTC's $700 million Equifax settlement was less than 1 percent of Equifax's $5 billion annual revenue at the time of the breach. The Marriott $123 million settlement was 0.06 percent of Marriott's $20 billion annual revenue. The Anthem $115 million was 0.5 percent of Anthem's $79 billion annual revenue. The PIPC's $409 million is structurally higher than all four.
The closest the US has come to a PIPC-style structure is the 2022 American Innovation and Choice Online Act, which would have given the FTC and state AGs the authority to seek civil penalties of up to 15 percent of revenue for certain privacy violations. The bill died in committee. The 2023 APRA had a similar revenue-proportional structure for the largest companies. The APRA died in committee. The 2024 Kids Online Safety Act (KOSA) had a per-violation structure for minors' data. KOSA passed the Senate in 2024 and has been stuck in the House since. The 2025-2026 state laws have moved on different problems (data brokers, neural data, AI training), not on breach penalties.[14]
What Enterprise IT Should Expect for Incident Cost Planning in 2027 and Beyond
The Korean fine should reset US enterprise IT's incident-cost planning model. The current US planning model assumes a breach fine in the $1-to-$5-per-record range, based on the Equifax and Marriott precedents. The PIPC fine at $10.89 per record, on a regulator's official affected-population count, is more than double the upper bound of the US planning model.
Three operational implications for the next 18 months:
1. The state-AG civil-penalty ceiling is the new floor. California's CCPA $7,500-per-violation maximum is the highest US per-violation cap on the books. A breach affecting one million CCPA-covered consumers could theoretically expose a company to $7.5 billion in civil penalties, before any actual damages. The Tractor Supply precedent at $1.4 million is a low-water-mark. State AGs have the civil-penalty structure. The trigger is the first multi-state breach that the AGs pursue in coordination, and the coordination is already happening (the Equifax, Anthem, and Marriott settlements were all multi-state). The 2026 PIPC fine gives state AGs a public benchmark to point to.[10][11][12]
2. The cyber-insurance pricing model is going to reprice. The largest cyber-insurance policies on the US market are written with breach-cost assumptions in the $2-to-$4-per-record range, based on the Equifax and Marriott precedents. The PIPC fine at $10.89 per record is well above the upper bound of those assumptions. The 2027 cyber-insurance renewal cycle is the first chance for the underwriters to reprice. Expect higher premiums for the largest coverage tiers and tighter sublimits for regulatory fines.[15]
3. The M&A and IPO diligence model is going to change. The Yahoo $350 million Verizon price concession was the largest per-record US settlement, and it was an M&A price concession, not a regulatory fine. The PIPC fine creates a new precedent for a regulatory fine at a similar per-record scale. The 2026-2027 M&A cycle is the first chance for buyers to start pricing in the PIPC precedent. The diligence question for every US data-handling target is now "what would a PIPC-equivalent regulator do with this company?" That question was not being asked in 2025.[8]
What It Means for the US Privacy Fight
The PIPC fine does not change US law. It does change the political environment. The civil-society coalition that has been pushing for the APRA, the KOSA, and the state privacy laws has a new public benchmark to point to. The argument that "US privacy law is structurally weaker than South Korea's enforcement" was a true abstraction before June 11. It is now a public fact with a number attached.
The $409 million number will be cited in every state-AG press release, every federal-privacy-bill hearing, and every state-privacy-law coalition letter for the rest of 2026 and 2027. The 2027 California legislative session, the 2027 New York session, the 2027 Colorado session, and the 2027 Connecticut session are the next political moments when revenue-proportional civil-penalty structures are on the table. The PIPC fine is the talking point that makes those proposals politically plausible. The first US state to put a PIPC-equivalent revenue-percentage ceiling on the books is the state that gets the credit for closing the gap.
The structural fact is the structural fact: the US has not produced a breach fine in the $400 million range, and South Korea has. The US does not have a federal privacy regulator with the authority to produce one. The state AGs have the per-violation structure but not the revenue-proportional ceiling. The PIPC fine is the public benchmark, and the public benchmark is the political leverage.
What You Can Do Today
- Read the BleepingComputer primary source for the fine. The Sergiu Gatlan article from June 11 is the cleanest English-language source for the PIPC finding, the 624.6 billion won figure, the 37.55 million affected population, and the suspect details. Bookmark it. Send it to your state representative when they ask why the US needs a federal privacy law.[1]
- Read the FTC's Equifax settlement page. The FTC's enforcement page for the 2017 Equifax breach is the primary US source for the $425 million consumer-restitution fund and the 147 million affected population. The math the FTC publishes is the math that the state-AG coordination effort was based on. The FTC's number is the floor.[4][5]
- Email your state AG if you live in Colorado, Connecticut, or California. The CPA, the CTDPA, and the CCPA/CPRA have the per-violation civil-penalty structure. The Tractor Supply settlement is the low-water-mark. The PIPC fine is the new benchmark. Your state AG's office has open investigations. The next 18 months are the window when the per-violation math is being set.[10][11][12]
- Email your US representative and senators about the APRA. The American Privacy Rights Act has been stalled in committee since 2024. The 2026 PIPC fine gives the APRA's proponents a new talking point. The APRA's revenue-proportional structure is the closest US federal proposal to a PIPC-equivalent civil-penalty ceiling. The first 30 days after the fine is when the talking point is most useful.[14]
- Ask your employer (or your client) what the breach-cost model is. If your employer is a US company that handles personal data, the incident-cost model is probably based on the Equifax or Marriott precedents. The PIPC fine at $10.89 per record is more than double the upper bound. The 2027 cyber-insurance renewal cycle is the first chance for the model to reprice. The 2026 internal conversation is the chance to get ahead of it.[15]
- Watch the PIPC precedent. The PIPC has been the de facto global benchmark for data-breach fines since the 2022 PIPA amendments raised the civil-penalty ceiling. The Coupang fine is the largest single-breach fine in PIPC history. The 2026-2027 PIPC enforcement actions are the next datapoints. If the PIPC fines a second Korean company at the same scale, the US regulatory gap is no longer a one-off story. It is a pattern.
- Watch the New York and California privacy-law sessions in 2027. The New York surveillance pricing ban, signed in May 2026, is the most recent state privacy-law move. California S.B. 2564, the surveillance-pricing bill, is moving through the legislature with EFF and CDT support. The 2027 California and New York sessions are the next political moments when a PIPC-equivalent revenue-proportional civil-penalty structure could land. Watch the bill texts.[12][13]
The Bottom Line
South Korea's PIPC fined Coupang $409 million on June 11, 2026, for a single breach that exposed 37.55 million people's data. The per-record math is $10.89. The 2017 Equifax settlement, the biggest US data-breach fine in history, was $4.76 per person on the full $700 million, or $2.89 per person on the $425 million consumer-restitution fund. The 2018 Marriott settlement was $0.36 per record. The 2015 Anthem settlement was $1.46 per record. The US has no federal privacy regulator with the authority to fine a single breach anywhere near $10 per record. The FTC's Section 5 authority is bounded by what a court will accept under "unfair or deceptive" standards. The state AGs in Colorado, Connecticut, and California have the per-violation structure, with caps under $10,000 per violation, but no state has yet used the structure to produce a fine in the $100 million range. The 2027 California and New York legislative sessions are the next political moments when a PIPC-equivalent revenue-proportional ceiling could land. The PIPC fine is the public benchmark, and the public benchmark is the political leverage. The argument that "US privacy law is structurally weaker than South Korea's enforcement" is no longer an abstraction. It is a $409 million fact.
Sources
- BleepingComputer: "Coupang hit with record $409 million data breach fine in Korea" (Sergiu Gatlan, June 11, 2026, with the PIPC 624.681 billion won figure, the 37.55 million affected population, the suspect details, the 33.7 million account disclosure, the 1.685 trillion won compensation plan, and the SK Telecom parallel)
- Yahoo Finance: "South Korea fines Coupang $409 million in country's largest data breach penalty" (June 11, 2026)
- Korea Times: "Korea fines Coupang W409 million for massive data breach" (June 11, 2026, PIPC primary source reference)
- Federal Trade Commission: "Equifax Data Breach Settlement" enforcement page (FTC/CFPB/50 states and territories, 147 million people, $425 million consumer-restitution fund)
- Federal Trade Commission: Equifax data breach settlement announcement, July 22, 2019 (FTC, CFPB, and 50-state coalition, $700 million total settlement, including the $425 million consumer-restitution fund)
- Wikipedia: Marriott International (the 2018 Starwood breach disclosed November 30, 2018, originally 500 million records revised January 2019 to less than 383 million; UK ICO fine of £18 million under GDPR; subsequent US class action settlement reported at $123 million in legal press)
- Wikipedia: Anthem (the 2015 data breach of approximately 78.8 million records and the 2017 class-action settlement reported at $115 million, the largest US health-insurance data breach settlement on record)
- Wikipedia: Yahoo! data breaches (2013-2014 breaches affecting all 3 billion accounts, Verizon $350 million price reduction in October 2017)
- Korean Law Information Center: Personal Information Protection Act (PIPA) text and amendments (the 2022 amendment raising the PIPC maximum administrative-fine ceiling on revenue is the statutory basis for the Coupang fine)
- Colorado General Assembly: HB22-1057, the Colorado Privacy Act (effective July 1, 2023, exclusive Colorado Attorney General enforcement, $20,000 per violation civil-penalty ceiling under the Colorado Consumer Protection Act)
- Wikipedia: State privacy laws of the United States (covers the Connecticut Data Privacy Act, including the $5,000-per-violation ceiling and exclusive attorney general enforcement)
- California Privacy Protection Agency: 2025 enforcement announcements (including the agency first major CCPA per-violation enforcement action against Tractor Supply Co.; per-violation structure under the CCPA/CPRA is $2,500 per violation or $7,500 per intentional violation or violation involving a minor)
- California Legislature: S.B. 2564 (2025-2026 session, surveillance pricing ban, EFF and CDT coalition support, 2026 legislative cycle)
- Wikipedia: American Privacy Rights Act (the 2024 federal privacy bill stalled in the 118th Congress; the closest US federal proposal to a PIPC-equivalent revenue-proportional civil-penalty ceiling for the largest data handlers)
- Marsh: 2025 Cyber Insurance Market Update (per-record breach-cost assumption model, the $2-to-$4-per-record range that the US cyber-insurance market is currently pricing, the 2027 repricing window)