Coupang hit with record $409 million data breach fine in Korea

2026-06-11T13:23:39Z5ec0330c99bdecb1df2aa2fe3dae8311222d0a0884100226e9e0ebed2b3dadbd
BitLockerCISA-BOD-26-04CVE-2026-5027CoupangExchange-XSSIvanti-SentryJDY-botnetLangflowMiasmaPeopleSoftShinyHuntersWindows-zero-daysdata-breachnpm-securitypatchingpath-traversalregulatory-finesupply-chainuniversity-breachzero-day

What happened

A set of high-impact security developments: South Korea’s PIPC fined Coupang ~624.6 billion won ($409M) after a breach affecting ~37M customers; CISA issued Binding Operational Directive 26-04 forcing rapid patching of critical exploited flaws for federal agencies; multiple actively exploited and recently patched vulnerabilities were disclosed including a maximum-severity Ivanti Sentry RCE and Microsoft Exchange/Windows zero-days. A high-severity path traversal in Langflow (CVE-2026-5027) is being actively exploited to write arbitrary files, while supply-chain and credential-theft risks rose (

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
5ec0330c99bdecb1df2aa2fe3dae8311222d0a0884100226e9e0ebed2b3dadbd
Enrichment time
2026-06-11T13:23:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.