Disclosure: Some links on this page are affiliate links. If you purchase through them, we may earn a commission at no extra cost to you. Full affiliate disclosure.

Gangnam Unni is a South Korean platform that connects people with cosmetic surgery clinics. On September 4, 2026, an API used to look up consultation records was accessed abnormally. The operator, Healing Paper, blocked that route — and then found the same attacker trying a different path the next day.
The confirmed total is 219,665 affected users: roughly 160,000 in South Korea, 48,000 in Japan, 4,218 in Taiwan, 1,591 in Thailand, 481 in mainland China and 5,308 elsewhere.
The count is not what makes this one different. What makes it different is that the stolen data includes consultation photographs, the reason each person sought treatment, and how far along their treatment was. There is no reset for that.
Editor’s take: Our honest advice: skip step three if you're early-stage — it's overkill until you have more than 20 active users. Coming back to it later is faster than doing it twice.
The line that should stick is in the headline: passwords can be reset, photographs cannot. This is the category of breach where the usual advice is useless, because there is no credential to rotate and no way to unpublish the file. It also shows how much damage a single misused API can do without anyone "hacking" anything — authorisation failures look like normal traffic until the data is already out.
The exposure splits into two layers, and the second one is the problem.
The first is ordinary identity data of the kind that appears in most breaches: name, phone number, email address, date of birth, gender, place of residence, social media account IDs, IP address and device details. Unpleasant, but familiar.
The second layer is specific to a medical aesthetics platform:
Read that list as what an outsider can now reconstruct: this person's face before a procedure, what they wanted changed, where they had it done, and when. Korean media reporting noted that the data can reveal both health conditions and appearance insecurities.
Breach response advice is built around credentials, because credentials are replaceable. If a password leaks, you change it. If a card number leaks, the bank issues a new one. The whole playbook assumes the exposed secret can be revoked.
A photograph of your face has no revocation mechanism. Neither does the fact that you consulted about a specific procedure on a specific date. Those are permanent attributes, and once they are in a file with your name, phone number and date of birth attached, they are permanently linkable to you.
This is the same reason the IDScan driver's license breach was graver than its record count suggested. Government ID numbers cannot be reissued either. What is different here is the addition of imagery, which converts a fraud risk into a personal one.
South Korean security professionals quoted in local coverage warned about two follow-on attacks, and both follow directly from what was taken.
The first is impersonation. An attacker who knows your clinic, your doctor and your appointment timing can send a convincing message about a promotion, a follow-up visit or a billing issue. That message arrives with details no generic scammer would have.
The second is worse. The reported concern is that operators may threaten to publish pre-procedure photographs and treatment records unless payment is made. No such secondary harm had been reported at the time of disclosure — but the material required to attempt it is now in circulation, and for a platform whose users may not have disclosed these procedures to employers, family or partners, the use is obvious.
Healing Paper says it reported the incident to the Korea Internet & Security Agency and requested a police investigation. It has also opened a lookup on its official site, available for 30 days after the notice, where users can check whether they were affected.
The detail worth dwelling on is the entry point. This was not stolen credentials or an unpatched server — it was an API used to query consultation records being accessed in a way it was not intended to support.
That pattern keeps recurring, and it is harder to defend against than a missing patch because nothing is technically broken. The endpoint works as designed; it simply answers more questions than it should, to more callers than it should. Rate limiting and authorisation checks on object-level access are the controls that matter, and they tend to be added after an incident rather than before.
Note also the timing. The attacker came back through a second path the day after the first was closed. Whatever else this was, it was not opportunistic — someone knew the system well enough to have a fallback route ready.
The part you can still control: how much is findable about you elsewhere. The photographs are gone, but removing broker records cuts the links an attacker would use to connect this file to your employer, your family and your accounts.
For the broader sequence after any exposure, our data breach response guide walks through triage in order.
Gangnam Unni rebranded in July and announced overseas expansion. Two months later it is disclosing a breach of 219,665 users, including medical imagery, to a user base spread across Korea, Japan, Taiwan and Thailand. Growth and security investment were not moving at the same speed.
The general lesson is not "avoid medical platforms." It is that we have one breach response playbook and it does not fit every category. When the exposed data is a password, the playbook works. When it is a photograph of your face attached to the thing you were self-conscious about, the playbook has nothing to offer, and the only real defence was not storing it in a reachable place to begin with.
This account is based on the operator's public statement and on reporting about the exposed interface.
On September 4, 2026, an API used to look up consultation records was accessed abnormally. Healing Paper blocked the route, then found the same attacker trying a different path on September 5. A total of 219,665 users across South Korea and overseas were affected.
The disclosed fields cover names, phone numbers, email addresses, dates of birth, gender, place of residence, social account IDs, IP addresses and device details, plus treatment information and procedure-related payment details. Full card numbers were not among the reported fields.
Consultation photos and treatment reasons cannot be reissued. A password is changed in a minute and a card is cancelled with a phone call. A pre-procedure photograph linked to your name and the reason you sought treatment is permanent and directly usable for blackmail.
Healing Paper reported 219,665 affected users: roughly 160,000 in South Korea, 48,000 in Japan, 4,218 in Taiwan, 1,591 in Thailand, 481 in mainland China and 5,308 elsewhere.
Use the official lookup within the 30-day window, treat any clinic or platform message as untrusted and navigate to the site directly, watch for extortion attempts referencing photos or treatment, and reduce what data brokers hold, since brokers let an attacker link a leak like this to the rest of your life.
