광고

쿠팡, 과징금 6249억원 맞았다..3755만명 개인정보 유출

최애리 기자 | 기사입력 2026/06/11 [12:44]

▲ 김범석 쿠팡 Inc 이사회 의장.     ©브레이크뉴스

 

브레이크뉴스 최애리 기자= 정부가 대규모 개인정보 유출 사고를 일으킨 쿠팡과 쿠팡풀필먼트서비스(CFS)에 총 6249억원 규모의 과징금을 부과했다. 이는 지난해 SK텔레콤 유심 정보 유출 사고에 부과된 과징금 1347억원의 4.6배를 웃도는 역대 최대 규모다.

 

개인정보보호위원회는 지난 10일 제11회 전체회의를 열고 개인정보 보호법을 위반한 쿠팡과 쿠팡풀필먼트서비스에 총 6249억2900만원의 과징금과 1680만원의 과태료를 부과하기로 의결했다고 11일 밝혔다. 

 

개인정보위는 과징금과 과태료 부과 외에도 시정명령, 결과 공표, 개선 권고, 검찰 고발 조치를 함께 결정했다.

 

이번 처분 안건 가운데 개인정보 유출 사고와 관련해 쿠팡에는 과징금 4235억7500만원과 과태료 1680만원이 부과됐다.

 

▲ 정부가 개인정보 유출 사고를 낸 쿠팡에 역대 최대 과징금을 부과했다. 조사 결과 회원 3322만명과 비회원 최소 433만명의 개인정보가 유출된 것으로 확인됐다. 추가된 피해자는 비회원들로 쿠팡 회원이 배송지 목록에 등록해 둔 가족이나 지인의 이름, 전화번호, 주소다.  © 뉴시스


조사 결과 유출된 개인정보는 쿠팡 회원 3322만명과 비회원 최소 433만명 등 총 3755만명 이상에 달하는 것으로 확인됐다. 이는 지난 2월 정부 민관합동조사단이 발표한 규모보다 388만명 늘어난 수치다.

 

특히 비회원 피해자 상당수는 쿠팡 이용자가 배송지로 등록해 둔 가족이나 지인의 이름, 전화번호, 주소 등 개인정보가 유출된 사례로 파악됐다.

 

유출된 정보에는 회원 이름과 이메일 주소는 물론 배송지 정보 6398만건이 포함됐다. 여기에는 이름, 전화번호, 주소, 공동현관 비밀번호 일부 정보가 담겨 있었다. 일부 페이지에서는 마스킹 처리되지 않은 비밀번호까지 노출된 것으로 조사됐다.

 

또한 회원 5만8000명의 주문일, 상품명, 수량, 가격 등 약 27만건의 주문 내역도 유출됐다. 해커가 보낸 협박 메일에는 성인용품과 속옷 구매 내역 등 민감한 사생활 정보도 포함된 것으로 드러났다.

 

개인정보위는 이번 사고가 고도의 해킹 기술보다 쿠팡의 기본적인 보안 관리 부실에서 비롯된 것으로 판단했다.

 

정보를 탈취한 인물은 과거 쿠팡에서 인증 시스템 개발에 참여했던 전직 직원으로 확인됐다. 그는 퇴사 전 확보한 인증 서명키를 이용해 위조된 인증 토큰을 생성한 뒤 정상적인 로그인 절차 없이 시스템에 접근해 개인정보를 빼낸 것으로 조사됐다.

 

쿠팡은 해당 서명키를 암호화하지 않은 채 관리했으며, 관련 직원이 퇴사한 이후에도 키를 교체하거나 폐기하지 않은 것으로 나타났다.

 

이상 징후를 탐지하는 모니터링 체계도 제대로 작동하지 않았다. 해커는 단 16개의 인터넷 주소(IP)를 이용해 총 1억4800만회에 달하는 공격을 시도했으며, 이 가운데 1억1700만회가 특정 한 달 동안 집중됐지만 쿠팡은 이를 탐지하지 못했다.

 

사고 발생 이후 대응 과정에서도 문제점이 확인됐다. 쿠팡은 추가 유출 사실을 인지하고도 법정 통지 기한인 72시간을 넘겨 피해 사실을 알렸으며, 주소와 전화번호가 유출된 비회원들에게는 별도의 통지를 하지 않은 것으로 조사됐다.

 

또 내부 규정상 즉시 파기해야 하는 탈퇴 회원 배송지 정보 246만건과 계좌번호 31만건 등을 보관하고 있었으며, 일부 정보는 실제 유출 피해로 이어졌다.

 

정부 조사 과정에서 증거 보전 명령이 내려진 이후에도 약 5개월 분량의 웹 접속 로그가 수동으로 삭제된 사실이 확인됐다. 이로 인해 정확한 피해 규모와 유출 범위를 확인하는 데 어려움이 발생했다고 개인정보위는 설명했다.

 

개인정보위는 쿠팡에 인증체계와 키 관리 시스템 전면 개선, 비회원 대상 유출 사실 통지, 재발 방지 대책 마련 등을 명령했다. 또한 처분 결과를 쿠팡 홈페이지에 공표하도록 했다.

 

▲ 개인정보보호위원회가 3750만명의 개인정보 유출 사고를 낸 쿠팡에 과징금 총 6246억 8100억 원을 부과하기로 11일 의결했다. 사진은 이날 서울 송파구에 있는 쿠팡 본사 모습. 2026.06.11.   © 뉴시스


한편, 쿠팡 측은 이번 개인정보보호위원회 처분과 관련 "개인정보 유출 사고로 인해 고객과 국민께 심려를 끼쳐드린 점에 대해 사과드린다. 개인정보 보호 프레임워크를 더욱 강화하고 새로운 의지로 고객 신뢰 회복을 위해 노력하겠다"고 밝혔다.

 

이어 "다만, 작년 데이터 유출 사태와 관련 2차 피해를 방지하기 위한 선제적 조치와 명확한 사실관계에 근거한 설명이 개인정보위원회의 결정에 충분히 반영되지 못한 점 유감스럽게 생각한다"면서 "공식 의결서를 수령한 후 법적 절차를 통해 사실관계가 명확하게 규명되길 기대한다"고 법적 대응을 시사했다.

 

아울러 송경희 개인정보위원장은 쿠팡 측이 유감을 표명하며 법적 대응 입장을 밝힌데 대해 "우리 처분은 법과 원칙에 근거해 숙고 끝에 타당하게 내려진 것"이라며 "만약 쿠팡이 소송을 제기한다면 적극 대응하겠다"고 말했다.

 

*아래는 위 기사를 '구글 번역'으로 번역한 영문 기사의 [전문]입니다. '구글번역'은 이해도 높이기를 위해 노력하고 있습니다. 영문 번역에 오류가 있을 수 있음을 전제로 합니다.<*The following is [the full text] of the English article translated by 'Google Translate'. 'Google Translate' is working hard to improve understanding. It is assumed that there may be errors in the English translation.>

 

Coupang Fined 624.9 Billion Won... Personal Information of 37.55 Million People Leaked

 

The government has imposed a total fine of 624.9 billion won on Coupang and Coupang Fulfillment Services (CFS) for causing a large-scale personal information leak. This is the largest fine in history, exceeding 4.6 times the 134.7 billion won fine imposed last year for the SK Telecom SIM card data leak.

 

The Personal Information Protection Commission announced on the 11th that it held its 11th plenary meeting on the 10th and resolved to impose a total fine of 624.929 billion won and an administrative penalty of 16.8 million won on Coupang and Coupang Fulfillment Services for violating the Personal Information Protection Act.

 

In addition to imposing fines and administrative penalties, the Commission also decided on corrective orders, public announcement of results, recommendations for improvement, and referral to the prosecution. Among the sanctions identified in this round, Coupang was fined 423.575 billion won and surcharged 16.8 million won in connection with the personal information leak incident.

 

The investigation confirmed that the leaked personal information affected a total of over 37.55 million people, including 33.22 million Coupang members and at least 4.33 million non-members. This figure represents an increase of 3.88 million people compared to the scale announced by the government's joint public-private investigation team last February.

 

In particular, a significant number of non-member victims were identified as cases where personal information, such as the names, phone numbers, and addresses of family members or acquaintances registered as delivery addresses by Coupang users, was leaked.

 

The leaked information included not only member names and email addresses but also 63.98 million pieces of delivery address data. This data contained names, phone numbers, addresses, and partial information regarding building entrance passwords. It was found that on some pages, even passwords that were not masked were exposed.

 

Additionally, approximately 270,000 order records, including order dates, product names, quantities, and prices, belonging to 58,000 members were also leaked. It was revealed that the blackmail emails sent by the hacker contained sensitive private information, such as purchase records for adult products and underwear.

 

The Personal Information Protection Commission determined that this incident stemmed from Coupang's failure in basic security management rather than from advanced hacking techniques.

 

The individual who stole the information was identified as a former employee who had previously participated in the development of Coupang's authentication system. Investigations revealed that he used an authentication signature key obtained before leaving the company to generate a forged authentication token, then accessed the system without following normal login procedures to steal personal information.

 

It was found that Coupang managed the signature key without encryption and failed to replace or discard the key even after the employee had resigned.

 

The monitoring system designed to detect anomalies also failed to function properly. The hacker attempted a total of 148 million attacks using only 16 internet addresses (IPs), with 117 million of these concentrated within a specific month, yet Coupang failed to detect them.

 

Problems were also identified in the response process following the incident. It was found that Coupang notified the public of the damage after exceeding the statutory 72-hour notification period, despite being aware of the additional data leak, and failed to provide separate notification to non-members whose addresses and phone numbers were leaked.

 

Furthermore, the company retained 2.46 million shipping address records and 310,000 bank account numbers of withdrawn members, which are required to be destroyed immediately under internal regulations; some of this information actually led to data breaches.

 

It was confirmed that approximately five months' worth of web access logs were manually deleted even after an order to preserve evidence was issued during the government investigation. The Personal Information Protection Commission explained that this made it difficult to determine the exact scale of the damage and the scope of the leak.

 

The Commission ordered Coupang to comprehensively improve its authentication system and key management system, notify non-members of the data leak, and establish measures to prevent recurrence. It also mandated that the results of the disposition be publicly announced on the Coupang website.

 

Meanwhile, regarding the Commission's disposition, Coupang stated, "We apologize for causing concern to our customers and the public due to the personal information leak incident. We will further strengthen our personal information protection framework and strive to restore customer trust with renewed determination." "However, we regret that the preemptive measures to prevent secondary damage related to last year's data leak and explanations based on clear facts were not sufficiently reflected in the decision of the Personal Information Protection Commission," they added, hinting at legal action by stating, "We look forward to the facts being clearly clarified through legal procedures after receiving the official resolution."

 

In addition, regarding Coupang’s indication of legal action, Personal Information Protection Commission Chairperson Song Kyung-hee stated, "Our decision was made reasonably after careful consideration based on law and principles," adding, "If Coupang files a lawsuit, we will respond actively."

기사제보 및 보도자료 119@breaknews.com
ⓒ 한국언론의 세대교체 브레이크뉴스 / 무단전재 및 재배포금지
 
  • 도배방지 이미지

광고
광고
광고