TechNewsReel
Live

Gangnam Unnie Breach Exposes Medical Records and Photos of 220,000 Users

Healing Paper reports a targeted API attack that leaked sensitive consultation images and treatment histories across multiple countries.

TechNewsReel Newsroom · September 8, 2026

Healing Paper, the operator of the beauty medical platform Gangnam Unnie, has confirmed a significant data breach that exposed the private medical and personal information of approximately 220,000 users. The incident, which occurred on September 4, 2026, highlights a critical vulnerability in the platform's API security.

According to company reports, the breach was executed through abnormal access to specific APIs used to retrieve consultation records. In total, 219,665 users were affected, representing roughly 2.2% of the platform's 9.9 million registered users. The impact was global: 160,000 victims were in South Korea, 48,000 in Japan, 5,308 in English-speaking and other countries, 4,218 in Taiwan, 1,591 in Thailand, and 481 in China. While a second hacking attempt on September 5 was successfully blocked, the initial intrusion resulted in the theft of extensive personal data, including names, phone numbers, email addresses, birthdates, genders, residence regions, social network login IDs, IP addresses, and device usage details.

High-Stakes Medical Exposure

Beyond basic contact information, the breach involved highly sensitive medical data. Leaked records include consultation photos, detailed treatment histories, payment records, the names of medical practitioners, and the specific dates of procedures. Gangnam Unnie, which launched in January 2015, serves as a primary hub for users to connect with beauty clinics and manage their cosmetic surgery records, making the nature of this leaked data uniquely invasive.

Risks of Secondary Crime

Industry experts warn that the exposure of pre-surgery photos and medical histories creates a severe risk of secondary crimes. A security industry source noted that perpetrators could use this private information for extortion or blackmail, threatening to leak sensitive images or treatment records to a victim's colleagues or on illegal websites to demand payment.

Healing Paper CEO Hong Seung-il has urged affected users to remain vigilant. "Please exercise caution regarding unsolicited text messages, calls, or emails that may exploit the leaked data," Hong stated, warning users that they should not respond to any requests for personal or financial information.

Regulatory Response

Healing Paper has reported the breach to the Seoul Gangnam Police Station, the Personal Information Protection Commission, and the Korea Internet & Security Agency (KISA). The company is now working with these authorities to investigate the full scope of the API vulnerability and mitigate further risks to its user base. Industry observers are now monitoring whether this incident prompts stricter security mandates for medical platforms handling biometric and photographic data.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.