
Personal information belonging to approximately 220,000 domestic and international users of Gangnam Unni, South Korea's leading cosmetic medical platform, has been leaked in a recent cyber security incident. Healing Paper, the company operating the platform, announced that the breach compromises not only basic identification data but also highly sensitive records, including plastic surgery consultation details, medical photos, and actual treatment histories, raising serious concerns over potential secondary harms such as targeted phishing and privacy violations.
According to Healing Paper's official notice, the security incident originated from an unauthorized, abnormal access attempt targeting an application programming interface (API) used to retrieve user consultation records on September 4. Although company systems detected suspicious activity and immediately blocked the initial breach route, subsequent investigations revealed that the same attacker attempted a secondary intrusion through an alternative route the following day on September 5.
The total number of affected accounts has been officially tallied at 219,665. While the majority of victims are domestic users numbering around 160,000, the platform's large international user base was also impacted. Affected international users include approximately 48,000 in Japan, 4,218 in Taiwan, 1,591 in Thailand, 481 in China, and 5,308 across English-speaking and other overseas regions.
The compromised datasets encompass a wide spectrum of user information. Beyond standard identifiers such as names, phone numbers, email addresses, dates of birth, genders, residential countries, social-login IDs, access IP addresses, and device specifications, the breach exposed deeply personal medical and aesthetic data. This includes specific cosmetic events and procedures users inquired about, hospital and doctor names, preferred appointment times, reasons for consultations, and photographs uploaded during the consultation process. Furthermore, records detailing actual treatments received, hospital visit dates, and partial payment details including amounts, methods, and transaction timestamps were also compromised.
Because the leaked fields disclose individual health conditions, aesthetic insecurities, and private medical choices, cybersecurity experts and industry observers warn that the incident carries a severe risk of secondary exploitation. Malicious actors could utilize combination data—such as facial photographs matched with precise medical histories—to launch highly convincing phishing scams, extortion attempts, or impersonation campaigns where fraudsters pose as partner clinics or platform customer service representatives.
In response to the crisis, Healing Paper stated that it has completed comprehensive internal system inspections and promptly reported the security lapse to the Korea Internet & Security Agency (KISA). The company formally requested a police investigation on September 6 and noted that it has secured digital clues to help identify the attacker. Affected individuals have been notified directly via personal notices, and a dedicated lookup service has been launched on the official Gangnam Unni Website allowing users to verify whether their specific data was exposed during a 30-day window.
Healing Paper has strongly urged all users to remain vigilant against suspicious text messages, phone calls, or emails leveraging the platform's name or partner hospitals to offer special discounts or event packages. Users are advised to refrain from clicking unverified links or disclosing private financial information.
[Copyright (c) Global Economic Times. All Rights Reserved.]

![[등록] 2026-09-01 15:48:31](/support/_updata/banner2/tl181982910_6749.png)



























