Personal information of 220,000 users of aesthetic medicine platform ‘Gangnam Sister’ leaked
Including consultation, reservation, and procedure information… A total of 219,665 people were affected, including 160,000 Korean users.
Quick Look
- Personal information of a total of 219,665 people, including 160,000 Koreans, was leaked from Healing Paper, the operator of the aesthetic medicine platform 'Gangnam Unni', due to abnormal access to the API.
- The leaked items include sensitive information such as consultation details, procedure information, and payment details, raising concerns about secondary damage.
AI-generated summary
Why It Matters
Healing Paper is a company that operates the aesthetic medicine information platform ‘Gangnam Sister’. On the 4th and 5th, a large-scale personal information leak occurred due to abnormal access through the API linkage function.
Personal information of approximately 220,000 domestic and international users was leaked from Healing Paper, the operator of the medical aesthetics platform Gangnam Unni.
There are concerns about secondary damages, such as impersonation of hospitals or the platform, as the leaked data includes consultation and reservation details as well as actual treatment information.
On the 7th, Healing Paper announced via a public notice that unauthorized access had occurred on the 4th through an API function used to retrieve consultation records, resulting in the leakage of some customers' personal information.
Healing Paper stated that after detecting the anomaly, it blocked the access path, but confirmed that the same attacker attempted to gain access again through a different route on the 5th.
According to Healing Paper, the total number of affected individuals was 219,665.
The majority of affected users were from South Korea, with approximately 160,000 individuals. Other affected countries include Japan (48,000), Taiwan (4,218), Thailand (1,591), China (481), and English-speaking and other countries (5,308).
The leaked data included names, phone numbers, email addresses, dates of birth, gender, country/region of residence, social network login IDs, access IP addresses, and device information.
Specifically, the leaked information also included event and treatment names requested during consultations, hospital names, doctor names, preferred reservation times, consultation motivations and statuses, and photos registered during consultations.
Information regarding interest, applications, and actual treatments, including visit and treatment dates, treating doctor names, payment amounts, methods, and timestamps, was also partially leaked.
Given that the leaked data includes sensitive information that could allow inferences about individuals' health conditions or concerns regarding their appearance, there are concerns that misuse of this information could lead to privacy violations and phishing attacks.
Healing Paper stated that it has notified affected users individually and enabled them to check their leaked information items on the Gangnam Unni website for 30 days.
Additionally, the company urged users not to respond to text messages, phone calls, or emails impersonating Gangnam Unni or hospitals, which offer discounts or hospital information and request clicks on links or the provision of personal and financial information.
What to Watch
AI outlook — possibilities, not facts
Initiation of investigation by relevant authorities such as the Personal Information Protection Committee
Very likely · Within weeks
Open Questions
- The specific identity and background of the attacker
- Whether leaked information is distributed on the dark web
- Specific vulnerabilities in the security system







