Cyber & AI intelligence
Wasteland.
Briefs indexed2462
Issues27
Published Mondays07:30 CT
▣ Breach GANGNAM-UNNI-MEDIC 2026-09-07

Gangnam Unni: Unauthorized API Access Exposes 219,665 Cosmetic Medicine Users

"Healing Paper, the Seoul startup behind the cosmetic-medical platform Gangnam Unni, confirmed on Monday that an attacker abused an application programming interface tied to its consultation-records function and walked…"

Healing Paper, the Seoul startup behind the cosmetic-medical platform Gangnam Unni, confirmed on Monday that an attacker abused an application programming interface tied to its consultation-records function and walked away with the personal and medical data of roughly 220,000 users across six markets. The company puts the precise figure at 219,665 affected accounts, a number reported consistently by Newsis, Chosun Ilbo, the Korea JoongAng Daily and The Herald Business, all citing Healing Paper's own notice and a Yonhap report. Headlines round it to 220,000; the company's own count is the more exact figure and the one defenders should cite. What separates this incident from a routine credential dump is the payload: not just names and phone numbers, but consultation photos, the names of the doctors and hospitals users approached, the procedures they actually underwent, and payment records. Healing Paper filed a police report on 6 September and self-reported the leak to the Korea Internet & Security Agency.

What Happened

According to Healing Paper's disclosure as relayed by Newsis and the English-language press, the intrusion began on Friday 4 September, when an abnormal access attempt was made against an API used to retrieve consultation histories. The company says it detected the anomaly in real time, cut off the access route immediately, and launched emergency security measures across its systems.

That did not end it. On Saturday 5 September, while remediation was still in progress, Healing Paper identified the same attacker attempting entry again through a different route. That path was also blocked. The company then ran a full sweep of its systems on the assumption that other endpoints exposed to the same technique might remain, and says it has since completed hardening across several fronts: strengthened authentication procedures, upgraded anomaly-detection for abnormal access, and a rebuild of its permission-verification logic.

Healing Paper states it has secured substantial evidence that could identify the attacker, and referred the case to its local police station on 6 September for a formal investigation. It also filed a voluntary breach report with KISA and says it has notified affected users individually. No threat actor has been named publicly, and no group has claimed the incident. CEO Hong Seung-il said the company takes the incident seriously, will cooperate fully with police and regulators, and will re-examine the effectiveness of its existing protections.

Accounts across the four outlets covering the disclosure are consistent on sequence, timing and totals. The reporting is uniformly downstream of the same company notice and Yonhap wire copy, which means everything currently known about this breach traces back to the victim's own account of it. Independent verification of the intrusion path, the dwell time and the completeness of the affected-user count has not yet been published by any regulator or third party.

What Was Taken

The victim breakdown by market, per Healing Paper: approximately 160,000 users in Korea, 48,000 in Japan, 4,218 in Taiwan, 1,591 in Thailand, 481 in China, and 5,308 across English-speaking and other countries. Note that the country figures as published sum to roughly 219,598 against a stated total of 219,665, a gap explained by the rounding of the Korean and Japanese counts rather than any discrepancy between sources.

The exposed fields, as itemised in the Korean-language reporting from Newsis and mirrored in the English coverage, fall into four tiers:

Identity and device data: name, contact number, email address, date of birth, gender, country and region of residence, social-login ID, app version, device information and connecting IP address.

Consultation applications: the name of the event or procedure enquired about, the doctor's name, the hospital or clinic name, and visitor information.

Consultation session data: consultation status, photographs submitted during the consultation process, requested appointment times, and the user's stated motivation for seeking the procedure.

Payment and treatment records: price, payment method, payment timestamp and payer information, alongside details of the procedure actually performed, the dates of the clinic visit and the treatment, and the name of the doctor who performed it.

That last tier is the one to sit with. This is not a list of people who browsed a beauty app. It is a record of which named individuals had which cosmetic procedures done, by which named surgeon, at which named clinic, on which date, for how much, and in many cases with a submitted photograph of the body part in question attached. Chosun Ilbo's coverage flags blackmail risk explicitly in its framing of the incident.

Why It Matters

Cosmetic surgery data occupies an unusual position in the threat model. In most jurisdictions it is elective, self-funded and frequently undisclosed to family, employers and partners. That combination makes it high-leverage for extortion in a way that, say, a pharmacy refill record often is not. A dataset pairing a real name and phone number with a specific procedure, a clinic, a surgeon and a photograph is close to purpose-built for individualised coercion, and Healing Paper itself is warning users about secondary harm.

The immediate and more likely abuse path is impersonation phishing. An attacker holding a user's name, their chosen clinic, their doctor's name, their appointment time and their payment amount can construct a message that is functionally indistinguishable from a legitimate clinic follow-up. Hong specifically warned users to treat unsolicited texts, calls and emails with suspicion, to never respond to requests for personal or financial data, and noted that Gangnam Unni does not solicit personal information by phone or SMS.

The cross-border dimension raises the regulatory stakes considerably. Japanese users alone account for roughly 22 percent of the affected population, with further victims in Taiwan, Thailand, China and English-speaking markets. This is a Korean company holding sensitive medical data on residents of at least six jurisdictions, which puts it in scope for multiple overlapping privacy regimes beyond Korea's own PIPA.

That international exposure is not incidental to the business model. Healing Paper spent 2026 aggressively expanding its foreign-patient operation. Its Unni Guide concierge service, launched in March, passed 1,600 completed bookings by August, growing roughly 30 percent month over month, with users from 73 countries and a physical service centre in Nonhyeon-dong, Gangnam. The Korea Times and Asia Business Daily both reported the milestone, though their published top-five country rankings differ slightly: the Korea Times lists Taiwan, the United States, China, Thailand and Singapore, while Asia Business Daily gives Thailand, Taiwan, the United States, China and Australia. The company also reported thirteenfold growth in Thai users and twelvefold growth in Greater China users in July year over year. The lesson generalises: an aggressive international growth curve multiplies the regulatory blast radius of any single API flaw, and the compliance surface expands faster than most security teams are resourced to cover.

Korean consumer platforms have absorbed a punishing run of breaches recently, with the Korea JoongAng Daily's own coverage referencing incidents at Weverse (420,000 users), Tving (approaching 40 million accounts) and Coupang. Gangnam Unni is smaller by headcount but arguably the most sensitive by data class.

The Attack Technique

The confirmed technical detail is narrow but instructive: unauthorised access to an API endpoint serving consultation records, blocked on detection, followed by a second attempt via a different route the next day. Healing Paper's remediation list is the strongest signal available about root cause. The company says it strengthened authentication procedures and rebuilt its permission-verification logic, which points toward a broken object-level or function-level authorisation weakness rather than an exploited software vulnerability or a credential compromise. In plain terms, an endpoint that returned consultation records appears to have insufficiently verified whether the requester was entitled to the records being requested.

The second-day attempt through an alternate path is the detail defenders should note. It indicates the flaw class was present at more than one endpoint, which is characteristic of authorisation gaps that stem from a design pattern replicated across an API surface rather than a one-off coding error. Healing Paper's decision to run a full-system sweep rather than patch the single reported endpoint was the correct call.

No attribution has been offered by the company, police or KISA. It is worth being explicit here about what this incident is not: there is no evidence linking it to ShinyHunters or the broader Scattered LAPSUS$ Hunters alliance, despite that group's documented and escalating focus on the health sector. Health-ISAC issued a 24 July advisory warning of a rise in successful ShinyHunters attacks against healthcare and medical-technology organisations, and Silent Push reported that Amgen confirmed via an SEC Form 8-K on 31 July that patient protected health information had been stolen from third-party cloud environments. Those campaigns are built on vishing against helpdesks, SSO account takeover and OAuth token abuse across SaaS platforms, a fundamentally different intrusion pattern from what Healing Paper describes. The relevant connection is contextual rather than causal: medical and health-adjacent data is under sustained, coordinated pressure from multiple directions right now, and platforms holding it should assume they are on somebody's target list.

What Organizations Should Do

Audit every API endpoint that returns per-user records for authorisation, not just authentication. A valid session token proving who someone is means nothing if the endpoint never checks what that identity is entitled to retrieve. Enumerate every endpoint accepting a user, booking or record identifier and confirm server-side ownership validation on each. Treat one confirmed instance as evidence of a pattern, exactly as Healing Paper did.

Rate-limit and anomaly-monitor record-retrieval endpoints as a distinct control class. Healing Paper's real-time detection is the reason this is a 220,000-record incident rather than a full-database one, and it deserves credit for that. Baseline normal per-account retrieval volume, alert on deviation, and ensure alerts reach someone with authority to cut an endpoint off out of hours. The second-day attempt landed on a weekend.

Classify medical and quasi-medical data by extortion value, not just regulatory category. Consultation photographs, procedure histories and surgeon names carry coercion potential far beyond what a generic PII risk register captures. Apply field-level encryption, aggressive retention limits and separate access controls to these fields. Ask directly whether consultation photos from closed cases need to remain retrievable through a production API at all.

Harden identity and helpdesk workflows against social engineering. Per the Health-ISAC advisory summarised by GeekFeed, ShinyHunters attack chains open with vishing aimed at getting helpdesk staff to reset passwords, change MFA methods or enrol new devices. Require out-of-band verification for any credential or MFA change, restrict who can perform enrolments, and enforce phishing-resistant MFA on every SSO-fronted application.

Map your third-party and SaaS data flows before you need to. The Amgen disclosure involved patient data held in vendor-run cloud environments. Inventory which external platforms and integrations hold customer records, audit the OAuth tokens and service accounts connecting them, and revoke standing access that nobody can justify.

Pre-build the multi-jurisdiction notification playbook. If you serve users across borders, know now which regulators you must notify and on what clock. Healing Paper reached KISA and its users quickly; a company that first discovers it holds Japanese and Taiwanese resident data during an active incident will not move that fast.

Warn users in the specific language of the likely attack. Generic advice to "be vigilant" is useless. Tell customers exactly what your company will never ask for by phone or SMS, and give them a single reporting channel, which is precisely what Hong did.

Sources: Gangnam Unni data breach exposes personal, medical records of 220,0... | Gangnam Unni data breach exposes personal information of nearly 220... | https://www.chosun.com/english/industry-en/2026/09/07/5UCWWIQEWBEMX... | Beauty app Gangnam Unni tops 1,600 foreign patient bookings in 5 mo... | 1,600 Requests from 73 Countries: Gangnam Unnie’s ‘Unnie Guide’ See... | Amgen Breach: What Our January Warning Tells Defenders - Silent Push | Health-ISAC warns of rising ShinyHunters data theft attacks on heal... | 강남언니, 22만명 환자정보 털렸다…시술내용도 유출 :: 공감언론 뉴시스 ::