Coupang's record fine dwarfs Korea's cyber insurance floor

Regulators plan to cut coverage requirements for 380,000 firms

Coupang's record fine dwarfs Korea's cyber insurance floor

Cyber

By Rod Bolivar

South Korea's data protection watchdog handed down a ₩624.7 billion fine against Coupang in June, the largest data protection penalty in the country's history — more than 600 times the ₩1 billion minimum insurance coverage still required of major data holders.

At the same time, regulators are moving to shrink the pool of companies required to carry that coverage at all, cutting mandatory enrollment from about 380,000 companies to around 200.

Under the current enforcement decree of the Personal Information Protection Act, companies that hold data on 1 million or more individuals and post revenue above ₩80 billion must carry a minimum of ₩1 billion in insurance coverage.

Coupang, whose leak affected tens of millions of people, reportedly carried personal data breach liability coverage of exactly that amount; divided across 10 million potential victims, the payout would come to roughly ₩100 per person.

That ₩1 billion ceiling now sits beside a very different number. On June 11, 2026, the Personal Information Protection Commission fined Coupang ₩624.7 billion after finding the company had failed to set up basic security management systems — split between ₩423.6 billion for the breach and ₩201.1 billion for unauthorized collection of online activity from about 11.17 million users.

The figure surpassed the previous record of ₩134.8 billion set against SK Telecom earlier in 2026, and a February 2026 amendment to the Personal Information Protection Act will raise the fine ceiling further, from 3% to 10% of revenue for cases involving gross negligence.

Regulatory penalties, in other words, are scaling into the hundreds of billions of won while the insurance floor beneath them has not moved.

The insurance industry wants that floor tiered by size. Proposals under discussion would require companies with 10 million or more data subjects and revenue above ₩1 trillion to carry at least ₩10 billion in coverage; those above ₩5 trillion, ₩50 billion; and those above ₩10 trillion, ₩100 billion.

A shrinking pool of covered companies

The Personal Information Protection Commission is separately pushing to raise the mandatory enrollment threshold itself, from revenue of ₩1 billion or more and 10,000 or more data subjects to revenue of ₩150 billion or more and 1 million or more data subjects — a change that would cut companies bound by the rule from roughly 380,000 to about 200.

The commission points to the difficulty of identifying which companies fall under the current rule, along with low awareness of the requirement among businesses, as its reasoning.

Industry representatives argue that removing the obligation for so many companies does not fix the underlying issue, and that better systems to track and enforce compliance would work instead.

Under current law, failing to comply with a corrective order can draw a fine of up to ₩30 million, though no such fine has reportedly ever been issued. Small and medium-sized enterprises, which typically have less capacity to pay claims out of pocket, would carry the greatest exposure if excluded — large companies can draw on their own funds after an incident, but smaller firms without insurance may struggle to manage a breach at all, let alone compensate victims.

The proposed rollback also follows the 2024 move to widen mandatory enrollment scope by just over a year, drawing criticism over inconsistent policy direction.

The market still isn't catching up

Breach volumes continue to climb well ahead of insurance enrollment. Personal data breach reports for the first half of this year reached 432, close to the 447 recorded for all of last year, while the volume of personal data leaked last year topped 100 million cases.

New cyber insurance contracts in the first quarter of this year totaled 1,617, up 5.2% from 1,537 a year earlier; in-force contracts stood at 5,381 as of the end of March, up 5.8% from 5,085.

Full-year 2025 figures show a similar pattern at a larger scale. Corporate cyber insurance contracts reached 7,683 for the year, up from 5,406 in 2024 — a 42% rise that pushed the total past 7,000 for the first time. Direct premiums climbed 68% over five years, from ₩47.8 billion to ₩80.1 billion, according to figures obtained by The Asia Business Daily through the office of lawmaker Lee Haemin, who is also pressing for a class action regime for data breach liability.

Set against its neighbors, Korea's cyber insurance market remains disproportionately small. Gallagher Re data put Korea's cyber premiums at about $3 million, roughly 0.02% of the global total, compared with about $39 million in Singapore and $5 million in Thailand — both smaller economies. The global cyber market is estimated at $16 billion to $20 billion in 2025 and is forecast to grow to between $30 billion and $50 billion by 2030, with Asia-Pacific expected to post the fastest growth rate as more economic activity moves online.

Insurers are building products ahead of the rules

Individual carriers are not waiting for the regulatory debate to settle. Hanwha General Insurance launched a Cyber Risk Management Center in November 2025, the first dedicated cyber risk division set up by a Korean insurer, formed through a three-way partnership with cybersecurity firm Theori and law firm Shin & Kim, The Korea Herald reported.

Samsung Fire & Marine established its own cyber risk team and, in May 2025, launched a policy aimed at small and mid-sized firms with under ₩100 billion ($72 million) in revenue and fewer than 3 million data subjects — the same segment regulators are now proposing to drop from mandatory coverage.

Corporate risk perceptions are shifting alongside the product response. The Allianz Risk Barometer 2026, published January 14, found cyber among Korea's top three business risks, consistent with its position as the top overall risk across Asia-Pacific, even as a separate amendment to the Personal Information Protection Act works to extend data breach insurance requirements to more organizations — running counter to the narrower enrollment threshold now under consideration.

"When personal data breaches are growing ever larger in scale, reducing the pool of companies subject to insurance while leaving the minimum coverage unchanged weakens the means by which victims can actually be compensated," an insurance industry official said. "There is a need to make coverage amounts realistic in line with company size and the number of personal records held, and to strengthen management and sanctions for non-enrolled companies."

Related Stories

Keep up with the latest news and events

Join our mailing list, it’s free!