South Korea's Financial Supervisory Service (FSS) fined Bithumb 180 million won (roughly $136,000) for breaching the Information and Communications Network Act, which requires companies to obtain explicit user consent before transferring personal data abroad.

The investigation found that Bithumb shared user information with multiple overseas exchanges without proper authorization. The FSS did not publicly name the recipient exchanges or specify which data fields were transferred. Bithumb has not commented on the fine.

The penalty lands within a standard enforcement range for this type of violation. South Korea's data protection regime treats unauthorized cross-border transfers as a direct breach of user rights, distinct from most Western frameworks that allow transfers under narrower safe-harbor rules.

Bithumb faced a major security incident in 2018 when hackers stole customer data, an episode that shaped the FSS's subsequent scrutiny of South Korean exchanges. The 180 million won fine reflects the regulator's focus on consent as the baseline control, not the severity of any breach or reputational harm.

The case underscores a tightening pattern: South Korean regulators have stepped up audits of major exchanges over the past two years, focusing on user protection and compliance with the revised Privacy Act. Bithumb, one of the country's largest platforms, is a regular target of such reviews. The desk understands no further investigation into this matter has been announced.