South Korea’s Personal Information Protection Commission (PIPC) on Wednesday imposed a combined $408 million (624.7 billion won) fine on Coupang and its logistics subsidiary, concluding that the U.S.-listed e-commerce company committed multiple violations related to a 2025 data breach that exposed the personal information of more than 33 million users. The regulator said Coupang failed to adequately manage authentication credentials, detect unauthorized access and comply with certain reporting and preservation requirements following the breach. The commission also stated that the company collected and stored online activity records from more than 11 million users without a sufficient legal basis.