Nearly 220,000 users of Gangnam Unni, a platform for comparing cosmetic procedures and clinics, were affected by unauthorized access discovered last week.
The affected users included about 160,000 in South Korea and roughly 48,000 in Japan.
Exposed information could include names, phone numbers, email addresses, clinics and doctors users contacted, preferred appointment times and, in some cases, treatment and payment details.
"When an external attack occurs, it leaves technical records such as access logs, and we found records of abnormal access," an official from Gangnam Unni told AJP. "Based on those records, we believe the data of about 220,000 users was exposed by a single attacker."
For some users, the records could reveal not only their identities but private choices about their appearance that they may never have intended to share with others.
Gangnam Unni is operated by South Korean health-tech company Healing Paper. According to an official notice posted by Healing Paper, abnormal access was detected on Sept. 4 through an application programming interface, or API, connected to consultation records. An API is a digital channel that allows different parts of an online service to exchange information.
The company said it detected the abnormal activity in real time, immediately blocked the access route and carried out emergency security measures across the service.
While the company was responding to the incident, the same attacker tried to access the system again through a different route on Sept. 5, according to the notice. Healing Paper said it blocked that route as well.
The company then conducted a full system review and completed several technical measures, including stronger authentication procedures, upgraded abnormal-access detection and a reworking of authorization checks.
What sets the case apart, however, is the type of information exposed.
A leaked phone number may lead to spam, while a password can be changed. A consultation photo or a record showing which cosmetic procedure someone considered can reveal something far more personal.
Healing Paper said the exposed records could also include consultation motives and status, as well as, for some users, payment details and information about procedures they actually received.
In its notice to affected users, Healing Paper warned of possible phishing attempts involving calls, messages or emails impersonating Gangnam Unni or medical institutions. It urged users to be particularly wary of contacts offering discounts, directing them to links or asking for personal or financial information.
Healing Paper said it voluntarily reported the breach to the Korea Internet & Security Agency (KISA) and individually notified affected customers. Users can check which categories of their information were exposed through the Gangnam Unni website for 30 days from the date of the notice.
The company also said it had gathered multiple indications that could help identify the attacker and requested a police investigation on Sept. 6 to determine exactly what happened and prevent further harm.
"Our priority is to cooperate fully with the police investigation," the official said. "We understand how concerned our users are, and we want to take responsibility and do what we need to do."
Chief Executive Hong Seung-il also apologized in the company's official notice.
"We take this incident very seriously and sincerely apologize once again to the customers who have trusted and used Gangnam Unni," Hong said.
He said the company would review the effectiveness of its existing safeguards, strengthen its security systems and make additional investments to prevent a recurrence.
The breach comes after a string of major data-security incidents that have put digital trust under pressure in South Korea.
The country's Personal Information Protection Commission, the government regulator responsible for enforcing privacy laws, received 447 personal-data leak reports in 2025, up 45.6 percent from 307 a year earlier. Hacking accounted for 276 of those cases.
Some of South Korea's biggest companies have been caught up in major data breaches.
Coupang reported a breach affecting more than 33 million users in November 2025. In June 2026, the Personal Information Protection Commission imposed a 624.68 billion won ($464 million) penalty on the e-commerce company over the breach and other privacy violations.
In July, the commission imposed a 53.98 billion won penalty on telecom carrier KT after personal information belonging to 16,647 subscribers was exposed. The regulator said 368 customers also suffered about 240 million won in fraudulent mobile-payment transactions linked to the incident.
Streaming platform TVING also came under investigation in June after unauthorized access to a database containing user information.
Against that backdrop, the Gangnam Unni case stands out because consultation photos and treatment records can reveal private decisions about a person's body and appearance.
Such information can be particularly sensitive in South Korea, where appearance can play an important role in how some young people view their social and employment prospects.
A 2019 study titled "Beliefs and trends of aesthetic surgery in South Korean young adults," published in Archives of Plastic Surgery, surveyed 103 South Korean job seekers aged 18 to 29.
Participants generally believed cosmetic surgery could improve their employment prospects, while dissatisfaction with appearance was the most common reason for undergoing or considering a procedure.
The small, self-selected sample was not representative of all young South Koreans, but the findings help illustrate why information about cosmetic procedures may be particularly personal for some users.
Meanwhile, South Korea is strengthening penalties for major personal-data breaches.
An amended privacy law taking effect on Sept. 11 will allow fines of up to 10 percent of total revenue in cases involving repeated leaks caused intentionally or through gross negligence within three years, or incidents in which such conduct affects at least 10 million people. The previous ceiling was 3 percent.
A platform built on information
Gangnam Unni launched in 2015 as a platform where users could compare clinics, treatment prices and reviews in one place.
The company later expanded overseas, introducing a Japanese-language service in 2019, followed by English in 2023, Thai in 2024 and Chinese in 2025.
By March 2026, more than 700,000 foreign users had completed consultation requests or reservations at South Korean dermatology and plastic-surgery clinics through the service, according to Healing Paper.
Japan was its largest overseas market. The company said in April that around 200,000 Japanese users had made new consultation requests or reservations over the previous year. Users from English-speaking markets including the United States, Canada and Britain increased 3.2-fold, while Thailand rose about 20-fold and Taiwan 25-fold, according to the company.
The expansion came alongside a broader rise in foreign demand for cosmetic and medical treatment in South Korea.
More than 2 million foreign patients received medical treatment in the country in 2025, according to the Ministry of Health and Welfare. About 1.31 million, or 62.9 percent, visited dermatology clinics. Dermatology and plastic surgery together accounted for more than 74 percent of the total.
In July, Healing Paper unified its overseas services under the brand name Unni as it sought to expand further in the global beauty-care market.
Compensation at home and abroad
Healing Paper said any compensation plan would cover affected users regardless of nationality.
"We plan to prepare and provide compensation as quickly as possible for all affected users, both in Korea and overseas," the official said.
The company has not yet announced the form or size of the compensation.
"We finished organizing the exposed data categories and notifying users on the evening of Sept. 7, while also completing the mandatory reporting procedures," the official said.
"We are now focused on preparing compensation and communicating with our customers." The official said the company is discussing the compensation plan internally and would announce details once finalized.
"Following this incident, we plan to redesign the overall service system and the way our information architecture is structured from the beginning," the official added.
"We believe the technical safeguards need to be strengthened as much as possible," the official added. "We will do our best."
As Gangnam Unni expands overseas, protecting the highly personal information its users provide is becoming part of the trust the platform sells.
The test now is whether users will still feel safe sharing the information that made the service useful in the first place.
Copyright ⓒ Aju Press All rights reserved.

