160,000 Korean users, 48,000 Japanese users affected

Leaked data includes consultation photos, hospital names, doctors' names and payment details

A promotional poster for Gangnam Unni. [Gangnam Unni]
A promotional poster for Gangnam Unni. [Gangnam Unni]

Healing Paper, the operator of Gangnam Unni, a cosmetic medical information platform, has suffered a data breach affecting roughly 220,000 users at home and abroad. The leaked data goes beyond basic personal details to include consultation and booking records as well as information on procedures users actually underwent, raising concerns that the breach could enable secondary harm such as phishing attacks impersonating hospitals or the platform.

According to Yonhap, Healing Paper announced that on Friday an unauthorized access attempt was made through an application programming interface used to retrieve consultation records, resulting in the leak of personal information belonging to some customers. The company said it blocked the access route immediately after detecting the anomaly but confirmed that the same attacker attempted to gain entry again the following day, Saturday, through a different channel.

Healing Paper said the total number of affected users was 219,665. By country, Korean users accounted for the largest share at about 160,000, followed by 48,000 in Japan, 4,218 in Taiwan, 1,591 in Thailand, 481 in China and 5,308 in English-speaking and other countries.

The compromised data includes names, phone numbers, email addresses, dates of birth, gender, country and region of residence, social network login IDs, IP addresses and device information.

Of particular concern is the volume of medical information involved. Data exposed includes the names of events and procedures users inquired about, hospital names, doctors' names, preferred appointment times, reasons for seeking consultations, consultation status and photos submitted during the consultation process. Information on procedures users expressed interest in, applied for or actually received — along with visit and procedure dates, the names of treating physicians, and payment amounts, methods and timestamps — was also found to have been leaked in some cases.

Because the information can reveal sensitive details about individuals' health conditions or appearance-related concerns, its misuse could lead not only to privacy violations but also to phishing scams.

Healing Paper said it has completed individual notifications to all affected users and has made it possible for them to check which of their data was leaked directly on the Gangnam Unni website for 30 days.

In addition, the company urged users not to respond to text messages, phone calls or emails impersonating Gangnam Unni or affiliated hospitals that offer discounts or clinic information while requesting clicks on links or the submission of personal or financial details.

"We take this incident with the utmost seriousness," Healing Paper CEO Hong Seung-il said in a notice. "We sincerely apologize again to our customers who have trusted and used Gangnam Unni."


won@heraldcorp.com