Healing Paper Co., Ltd. (Gangnam Unni)—Gangnam Unni breach exposed medical consultation data of ~220,000 users across Korea, Japan and other Asian markets
Healing Paper, operator of the Gangnam Unni cosmetic-procedure platform, disclosed that an unauthorized party accessed consultation records for 219,665 users via an API on September 4, 2026, with a second attempted breach the next day through a different channel. Exposed data included names, contact details, and sensitive medical information such as procedure and hospital names, consultation photos, appointment details, and payment records, affecting roughly 160,000 users in South Korea, 48,000 in Japan, and others in Taiwan, Thailand and China. The company reported the breach to the Korea Internet & Security Agency (KISA) and police.
Scoring Impact
| Topic | Direction | Relevance | Contribution |
|---|---|---|---|
| Data Security | -against | primary | -1.00 |
| User Privacy | -against | secondary | -0.50 |
| Overall incident score = | -0.725 | ||
Score = avg(topic contributions) × significance (high ×1.5) × confidence (0.64)
Evidence (2 signals)
Korea Herald reports Gangnam Unni data breach affecting ~220,000 users
Korea Herald reporting on the September 2026 breach of Healing Paper's Gangnam Unni platform, detailing the scope of exposed medical consultation data and the company's disclosure to KISA and police.
Sedaily reports Korean beauty app Gangnam Unni leaked data of 220,000 users
Sedaily (Korea) reporting on the Gangnam Unni breach, confirming user counts by country (Korea, Japan, Taiwan, Thailand, China) and the categories of medical/consultation data exposed.