Monday, August 3, 2026

Policy & Regulation

US investors trigger arbitration in Coupang data breach case

U.S. investors are seeking international arbitration against the South Korean government, alleging discriminatory treatment following a data breach involving nearly 34 million Coupang customer records.

US investors trigger arbitration in Coupang data breach case

On January 23, 2026, U.S. investment firms Greenoaks and Altimeter filed a notice of intent with South Korea’s Ministry of Justice to pursue investor–state dispute settlement (ISDS) arbitration under the U.S.-Korea Free Trade Agreement (FTA). The filing initiates a mandatory 90-day consultation period before formal arbitration can begin. Three additional U.S. investors—Abrams Capital, Durable Capital Partners, and Foxhaven Asset Management—have since joined the case. The investors allege that the South Korean government’s actions constitute an “unprecedented assault” on Coupang, which is headquartered in Seattle, Washington, but operates in South Korea, Taiwan, and Japan. According to the investors’ legal adviser, the government’s “shocking conduct” represents an “egregious violation of the Treaty” and a “longstanding campaign of discrimination” against the company, warning of potential claims for billions of dollars in damages over “attempted expropriation.”

The dispute stems from a data breach in which nearly 34 million Korean customers’ personal information was leaked. South Korea’s Ministry of Science and ICT stated on Wednesday that the breach was carried out by a former employee who had worked on the company’s authentication systems. While South Korea’s Personal Information Protection Commission (PIPC) investigated the breach, Coupang’s investors argue that only 3,000 accounts were actually affected. They characterize the regulatory response as a “discriminatory investigation.” Under current South Korean law, data breach penalties are capped at 3% of revenue, which would equal more than $800 million for Coupang. However, some local lawmakers have proposed raising the penalty cap to 10% and applying it retroactively, a move backed by the PIPC. South Korean president Lee Jae Myung has also publicly called for heavy penalties. In response to the pressure, Coupang replaced its former CEO, Park Dae-jun, with new CEO Harold Rogers in December.

According to Adam Farrar, senior associate at CSIS and senior geoeconomics analyst for APAC at Bloomberg, the case is amplifying broader U.S. claims of unfair treatment toward American technology firms. Speaking on Tuesday on the Impossible State podcast, Farrar noted: “The massive data breach [by Coupang] led to a series of investigations in the National Assembly and some very combative back and forth with Coupang and a series of executives over the past several months”. Investors argue that South Korea’s regulatory enforcement has been highly inconsistent, pointing to significantly lighter penalties imposed on other companies for data issues:

  • KakaoPay: Transferred 54 billion customer records to Alipay Singapore, but faced only a $10 million fine.
  • SK Telecom: Fined $91 million following a SIM card breach.

Why it matters

This legal escalation transforms a standard data security incident into a geopolitical flashpoint, testing the limits of the U.S.-Korea Free Trade Agreement and signaling potential trade risks for U.S. companies operating in South Korea.