The headline number from the Coupang data breach — more than 33 million user accounts — sounds like a major incident that implies a catastrophic failure of one of South Korea’s most important company’s cybersecurity programs. South Korea's Personal Information Protection Commission (PIPC) measures an incident by the “exposure and access” of data, and a disgruntled former engineer who retained and forged credentials did, in principle, have access to that many accounts over seven months. But what actually happened in this case was far narrower. According to Coupang internal investigation, the attacker downloaded data from just under 3,000 accounts, and later deleted it. However, it's worth noting that regulators dispute this finding as overly narrow. The breach exposed no financial information, and he did not transfer anything to any third party. Multiple investigations and reporting to date has surfaced no fraud, identity theft, or downstream misuse traced to the incident. All in all, this was mundane, not catastrophe.
Seoul’s response suggests the government wants to tell a different story. The PIPC investigation culminated in a $409 million fine—more than four times greater than the previous record-breaking fine. The company's SEC filing states that approximately $278 million of the fine is directly related to the incident while $132 million concerns a separate administrative fine concerning date collection. Their intrusive investigative process and the penalty together are meant to broadcast an unmistakable message: this was a massive cybersecurity failure by Coupang due to negligent security practices, that inflicted enormous harm — and Coupang must be punished severely ensuring radical, swift improvements and to deter every other company from replicating these mistakes.
The technical record supports none of that.
A single breach, standing alone with a headline number, often tells you very little about a company’s overall security practices. It can be a symptom of genuine negligence — under-investment, ignored warnings, decayed practices, poorly trained personnel. Or it can be what the sociologist Charles Perrow called a normal accident: small, unexpected failures are inevitable in society’s complex systems. The Coupang breach ran through the company's key management system, and the details — documented in the PIPC's own published investigation and in independent expert assessments Coupang commissioned — read like a case study Perrow could have written for normal accidents. Consider the chain of events the attack required:
- While still employed as a backend engineer, the attacker violated a company policy that keys must be retained only in the key management system. No monitoring mechanism existed to detect that specific violation.
- Before leaving, he identified this gap in the security process. He had a duty to report it. He did not — and three months after his departure, he exploited it.
- Using the stolen signing key and insider knowledge, he forged access credentials. Coupang's gateway server restricted entry to holders of valid tokens — and his forged tokens were cryptographically valid. The system flagged no anomaly because, from the system's perspective, none existed.
- He built scripts to collect data and transmit it to cloud storage — after he had left the company. There is no evidence that such a transmission ever occurred.
Coupang maintained current hardware and software for key management, layered authentication, and access monitoring. The failure was interactive — a policy violation invisible to monitoring, an unreported vulnerability, an offboarding gap, and an insider who knew exactly where the system’s seams of vulnerability were, because sealing those seams had been his job. That is the anatomy of a normal accident, not of a negligent enterprise.
None of this puts Coupang beyond scrutiny. The PIPC had a legitimate claim to investigate whether this failure was symptomatic of something deeper: negligence, under-investment, or systemically bad practice. That is what data protection regulators exist to do, and the technical depth of the investigation deserves credit. But all that depth uncovered no evidence that any of those things were true.
What should have been a proportionate response? It’s straightforward, and common cybersecurity practice. A breach by definition will expose a gap in a highly complex system that needs to be closed. And so Coupang – and other companies who learn from this incident – must close the accident pathway this breach revealed: credential revocation at offboarding, detection of keys stored outside the key management system, and continuous monitoring of token lifecycles. What government authorities need to do is confirm that the remediation is effective, and that the adjacent failure modes this incident made visible have been plugged. Post-incident verification, not massively punitive penalties that make headlines, is where a regulator actually changes outcomes for the better. The most durable defense against insider threats is a healthy working relationship between public authorities and private companies. Incidents are audited in an honest manner with the lessons learned from events shared across the industry.
A record punitive fine in response to a catastrophe that did not occur does the opposite. It teaches companies that candor and cooperation buy nothing. It converts an addressable security incident into an episode of techno-nationalist strife between allies. That serves no defender, no consumer, and no regulator. The only people it may benefit are the next set of attackers.
The Cipher Brief is committed to publishing a range of perspectives on national security issues submitted by deeply experienced national security professionals. Opinions expressed are those of the author and do not represent the views or opinions of The Cipher Brief.
Have a perspective to share based on your experience in the national security field? Send it to Editor@thecipherbrief.com for publication consideration.
Read more expert-driven national security insights, perspective and analysis in The Cipher Brief



