Approximately 220,000 Users’ Personal Information Leaked from Cosmetic Medical Platform Gangnam Unni, Including Hospital Names and Treatment Histories
- Input
- 2026-09-07 20:00:29
- Updated
- 2026-09-07 20:00:29

[Financial News] Personal information belonging to approximately 220,000 domestic and overseas users of Gangnam Unni, a cosmetic medical platform, has been leaked. The exposed data goes beyond names and contact details to include the names of treatments and hospitals users sought consultations for, actual treatment histories, and payment records, raising concerns about secondary harm from impersonators posing as hospitals or the platform.
According to Healing Paper on the 7th, an abnormal access attempt was made on the 4th against the API used to retrieve consultation records, resulting in the leakage of some customers’ personal information. Healing Paper blocked the access route immediately after detecting the suspicious activity in real time, but also confirmed that the same attacker attempted to break in again through a different route on the 5th. Healing Paper CEO Hong Seung-il apologized in a notice, saying, "The incident occurred as a result of an unexpected attack."
A total of 219,665 people were affected. South Korean users accounted for the largest group at approximately 160,000, followed by 48,000 in Japan, 4,218 in Taiwan, 1,591 in Thailand, 481 in China, and 5,308 in English-speaking and other countries. As Gangnam Unni has rapidly expanded its local user base in Japan and Taiwan, the impact has spread across national borders.
The sensitivity of the leaked information is the main concern. The exposed data was not limited to basic identifying information such as names, phone numbers, email addresses, dates of birth, gender, country and region of residence, social-login IDs, access IP addresses, and device information. It also included the events and treatment names for which users requested consultations, hospital and doctor names, preferred appointment times, reasons for seeking consultations, consultation status, and photographs uploaded during consultations. Some records also contained information on treatments users were interested in and treatments they actually received, dates and times of visits and procedures, treatment-doctor identifiers, payment amounts and methods, payment times, points used, and order identification numbers.
The information could reveal an individual’s health status or concerns about their appearance, giving the breach potentially serious repercussions. When facial photographs are combined with treatment histories, the data could be used for threatening messages or highly targeted phishing attempts, beyond ordinary spam. Impersonators who mention users’ names, hospital names, and appointment times could be difficult to distinguish from legitimate contacts. Industry observers are concerned that the incident could lead to privacy violations and financial fraud.
Healing Paper has completed a comprehensive inspection of its entire system. The company said it had completed technical measures including strengthened authentication procedures, enhanced detection of abnormal access, and a review of its authorization-verification logic. It voluntarily reported the breach to the Korea Internet & Security Agency (KISA) and requested an investigation from the police station with jurisdiction on the 6th. The company also said it had secured multiple clues that could help identify the attacker.
Affected users have been notified individually. On the Gangnam Unni website, users can directly check which types of information concerning them were leaked for 30 days from the date the notice was posted. The company urged users not to respond to text messages, phone calls, or emails from unclear sources, and to be especially wary of contacts that use Gangnam Unni or hospitals to encourage them to click links under the pretext of offering discounts or providing hospital information.
Healing Paper said it has disclosed its investments and staffing in information security through KISA’s information-security disclosures and has improved its protective measures in line with Information Security Management System (ISMS) certification requirements. Nevertheless, a vulnerability in API authorization verification was exploited. The Personal Information Protection Act requires separate consent and enhanced safeguards when processing sensitive information. Whether an administrative fine will be imposed is expected to depend on the findings of the Personal Information Protection Commission (PIPC)’s investigation.
[email protected] Kang Gu-gwi Reporter