
South Korea’s latest data-breach dispute is putting a potentially multibillion-dollar price tag on consumer privacy, a development that could matter to U.S. e-commerce, technology and cybersecurity companies operating in markets with increasingly aggressive data-protection rules. Coupang has rejected a proposed compensation plan that could have exposed the company to about $2.7 billion in payouts, keeping uncertainty over its ultimate liability alive.
Coupang notified the Consumer Dispute Mediation Committee of the Korea Consumer Agency on September 11 that it would not accept a recommendation to pay 100,000 won, or about $73, to each customer affected by a personal-data breach disclosed late last year. The committee had recognized Coupang’s responsibility to compensate 50 consumers who filed for collective dispute mediation.
The financial stakes were much larger than the initial group of 50 consumers. If Coupang had accepted the recommendation, the same compensation could have been extended to other affected customers who did not participate in the mediation process. That could have pushed the total payout to roughly 3.7 trillion won, or about $2.7 billion.
The decision comes after Coupang had already committed to a separate compensation program worth 1.685 trillion won, or about $1.2 billion. The company provided 50,000 won, roughly $36, in shopping vouchers to each of 33.7 million customers whose personal information was compromised.
Coupang said it had carefully reviewed the mediation proposal but determined that accepting it would be difficult. The company cited the measures it had already taken, including efforts to strengthen personal-information protection, as well as the broader implications of accepting the recommendation. Coupang has also said that no secondary harm from the breach has been confirmed so far.
For investors, the case highlights a growing financial risk for digital businesses: the cost of a major cybersecurity incident can extend well beyond regulatory penalties and technical remediation. Consumer compensation, litigation and changes to data-security practices can create additional liabilities that are difficult to quantify when millions of customers are affected.
The dispute also illustrates the potential importance of collective consumer remedies in large-scale data breaches. A recommendation involving only dozens of claimants could, under South Korea’s dispute-resolution framework, have financial implications extending to millions of affected customers.
Civic groups have criticized Coupang’s rejection, arguing that the company should accept greater responsibility for the breach. The groups have also called for stronger mechanisms to provide collective relief to consumers.
Coupang’s refusal means the mediation recommendation will not resolve the broader compensation dispute. Additional claims and civil litigation could determine how much further liability the company ultimately faces.
The episode is likely to be watched beyond South Korea as regulators and consumers worldwide demand greater accountability from companies that hold large volumes of personal information. For e-commerce and technology businesses, the case underscores how cybersecurity has increasingly become a balance-sheet issue as well as an operational one.





