Coupang hit with record $409 million data breach fine in Korea
2026-06-11T13:23:39Z•5ec0330c99bdecb1df2aa2fe3dae8311222d0a0884100226e9e0ebed2b3dadbd
BitLockerCISA-BOD-26-04CVE-2026-5027CoupangExchange-XSSIvanti-SentryJDY-botnetLangflowMiasmaPeopleSoftShinyHuntersWindows-zero-daysdata-breachnpm-securitypatchingpath-traversalregulatory-finesupply-chainuniversity-breachzero-day
What happened
A set of high-impact security developments: South Korea’s PIPC fined Coupang ~624.6 billion won ($409M) after a breach affecting ~37M customers; CISA issued Binding Operational Directive 26-04 forcing rapid patching of critical exploited flaws for federal agencies; multiple actively exploited and recently patched vulnerabilities were disclosed including a maximum-severity Ivanti Sentry RCE and Microsoft Exchange/Windows zero-days. A high-severity path traversal in Langflow (CVE-2026-5027) is being actively exploited to write arbitrary files, while supply-chain and credential-theft risks rose (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 5ec0330c99bdecb1df2aa2fe3dae8311222d0a0884100226e9e0ebed2b3dadbd
- Enrichment time
- 2026-06-11T13:23:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.