The operator of Gangnam Unni, South Korea’s leading cosmetic medical services platform, has disclosed a data breach affecting nearly 220,000 users in Korea and overseas. Healing Paper said in a Monday notice that an attacker gained unauthorized access to an application programming interface linked to its consultation records, with the intrusion occurring on Friday, September 4, 2026.
The exposed information includes user names, phone numbers, records of the cosmetic procedures each user inquired about or applied for, photos submitted for consultations, and payment details. Security researchers and the company warn that the combination of medical intent data and identity information raises the risk of impersonation scams targeting cosmetic surgery patients, including fraudulent messages offering clinic discounts.
Healing Paper said affected users were individually notified and can check which of their data was exposed through the Gangnam Unni website for 30 days. The company urged users not to respond to texts, calls, or emails impersonating Gangnam Unni or medical clinics that ask recipients to click links or hand over personal or financial information.
Gangnam Unni is a widely used platform for researching cosmetic procedures, comparing clinics, and booking consultations, including for international medical tourists traveling to South Korea for plastic surgery. The breach is the latest in a series of incidents affecting health-adjacent platforms that hold sensitive patient intent and treatment data outside the traditional hospital environment.