South Korea fines e-commerce giant Coupang $400M over data breach
摘要
韩国首尔个人信息保护委员会(PIPC)对 Coupang 开出 423.6 亿韩元(约 4 亿美元)罚款,这是该委员会针对数据泄露的最高罚款;同时额外对非自愿收集信息处以 201 亿韩元罚款。泄露涉及约 3750 万用户的姓名、联系方式、送货信息和订单历史,该平台为韩国最大电商公司,被视为韩国版亚马逊。韩国人口约 5000 万,泄露影响超过半数人口。Coupang 承认数据泄露,并称将加强安全措施,但表示将就罚款提出法律挑战;其 CEO 辞职,首席行政官临时担任 CEO。
荐读理由
韩国PIPC对Coupang的$400M罚款,针对缺乏认证签名密钥管理与访问控制的疏忽,暴露约3750万用户数据,凸显电商平台基础设施安全工程的硬性要求
原文
Korea fines e-commerce giant $400m over data breach affecting millions

Coupang is the dominant e-commerce company in South Korea
South Korea has hit online retail giant Coupang with a record fine of more than $400m (£299m) over a massive data breach that exposed the data of more than 30 million customers last year.
The fine is the largest ever issued by Seoul's Personal Information Protection Commission (PIPC) for a data breach.
The leak exposed the names, contact and delivery details and order histories of some customers of Coupang, South Korea's largest e-commerce platform often described as its equivalent of Amazon.
Coupang told the BBC it "deeply regrets the concern caused" and that it will strengthen its security measures, but added that it planned to challenge the PIPC decision.
The number of accounts affected by the incident represents more than half of South Korea's population of around 50 million people.
The PIPC on Wednesday announced a 423.6bn won fine over the personal data breach, and an additional 201bn won for the non-consensual collection of information.
The commission found that a lack of safeguards, including poor management of authentication signing keys and access controls, had resulted in the personal data of around 37.5 million users being exposed.
Coupang said that its explanations and measures to prevent further harm from the data breach "were not sufficiently reflected" in the commission's decision.
"Upon receiving the official resolution from the PIPC, we expect that the facts will be clearly established through legal procedures," said Coupang.
The decision follows a months-long probe into Coupang after allegations of the data leak surfaced in November.
The company is based in the US, but the majority of its revenue comes from South Korea.
Coupang told the BBC at the time that it was alerted to a breach involving 4,500 customer accounts in November and immediately reported it to the authorities.
But the company said that later checks found that nearly 34 million customer accounts - all in South Korea - were likely exposed. It added that the breach is believed to have begun as early as June through a server based abroad.
Following the breach, Coupang's boss Park Dae-jun resigned from his role, apologising for the incident. The platform's chief administrative officer Harold Rogers was appointed interim CEO.
South Korean firms faced a series of high-profile cyber-security incidents last year despite the country's reputation for tight data privacy standards.
Its largest mobile operator SK Telecom was fined nearly $100m over a data breach involving more than 20 million subscribers.
这条对你有帮助吗?