Key developments
South Korea fines Coupang over data misuse
South Korea's Personal Information Protection Commission imposed an approximately 624.6 billion won fine on Coupang on June 12, finding that the company leaked personal data of roughly 37.55 million people and collected data without authorization. The regulator also found that Coupang Partners collected and stored third-party website and app visit records for about 11.17 million users without consent, and ordered stronger oversight of advertising partners. Coupang Fulfillment Service received an additional 248 million won fine over unlawful employee-data use, including use of health-management weight data in industrial accident litigation.
Why it matters
The decision combines breach enforcement, behavioral-advertising data collection, and workplace privacy misuse in one of the largest privacy penalties reported today.
Sources & driving stories
BUSINESS HUMAN RIGHTS
Business Human Rights coverageMeta tested Rank One recognition for glasses
Wired's Dell Cameron reported that Meta used a Rank One Computing software license tied to a test version of the Meta AI app powering Ray-Ban and Oakley smart glasses. The license covered face recognition and liveness detection for up to 10 million facial templates, and code remnants appeared dormant in a consumer-distributed app build. Meta removed the functionality on June 5 after reporting; Rank One sells biometric tools to law-enforcement and military customers including the U.S. Marshals Service and Naval Criminal Investigative Service.
Why it matters
The reporting shows surveillance-grade biometric technology being evaluated for mass-market wearable cameras, raising consent, bias, and bystander-privacy concerns.
Sources & driving stories
WIRED · Dell Cameron
Wired coverage23andMe breach settlement reaches $46.75 million
Claims Journal's Chad Hemenway reported that the bankruptcy plan administrator for Chrome Holding Co., formerly 23andMe, agreed to distribute $46.75 million to victims of the 2023 data breach. Court records in the U.S. Bankruptcy Court for the Eastern District of Missouri show $32.5 million will resolve consolidated class-action lawsuits, with nearly $14.3 million already distributed to settlement administrator Kroll and about $13 million funded by cyber insurance. A June 10 filing said more than 255,860 claims have been resolved, while thousands remain unresolved and payouts range from $50 to $10,000 for extraordinary claims.
Why it matters
The settlement is a concrete privacy-litigation outcome for a breach involving genetic and family-relationship data affecting millions of users.
Sources & driving stories
CLAIMS JOURNAL · Chad Hemenway
Claims Journal coverageWorth noting
WORTH NOTING
Council of Europe HR breach claimed
Cybernews reported that ShinyHunters forum posts claimed theft of more than 297GB and 429,000 files from the Council of Europe, including HR and payroll records, though the organization had not confirmed the breach.
WORTH NOTING
UK plans under-16 social-media ban
CNET reported that the UK plans legislation before Christmas to bar under-16s from major social platforms by spring 2027, relying on age assurance and adding restrictions for older teens.
WORTH NOTING
Maine breach portal abused with fake filings
Security Magazine reported that Maine's attorney general took its public breach database offline after false Discord and VRChat breach reports were submitted, exposing a trust problem in public breach-notification systems.
Still unclear
OPEN QUESTION
How much identity proofing will age controls require?
The UK social-media proposal and related age-check debates could push platforms toward collecting IDs, biometrics, or other sensitive verification data at scale.
OPEN QUESTION
How should breach claims be verified faster?
The unconfirmed Council of Europe claim and Maine's fake breach filings show the tension between rapid public transparency and abuse-resistant validation.
